Privacy Policy
This Privacy Policy is issued by Hypersoft Technologies Limited, a technology and digital solutions company headquartered in India, serving clients across multiple industry verticals. It explains how we collect, use and protect the personal data that we process and control in respect of data principals and consumers, in accordance with the Digital Personal Data Protection Act, 2023 and other applicable laws.
Last updated: August 12, 2026
For purposes of this notice, “Site” refers to the corporate website and its subsidiaries. The terms “we,” “us,” and “our” refer to Hypersoft Technologies Limitedand its subsidiaries. “You” refers to you, as a user of our Site or our Service, and, where applicable, a “data principal” under the Digital Personal Data Protection Act, 2023. By accessing our Site, your IP address is captured automatically for information-security purposes and to enhance user experience.
Information We Collect
We collect “Non-Personal Information” and “Personal Information.” Non-Personal Information includes information that cannot be used to personally identify you, such as anonymous usage data, general demographic information we may collect, referring / exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit, and number of clicks.
Personal Information means any data about an individual who is identifiable by or in relation to such data. We capture your IP address automatically when you access our Site for information-security purposes. We collect additional personal data — such as your name, email address and message — only when you voluntarily provide it, for example through the “Write to us” section under the Contact page on this website, when you apply for a role, or when you otherwise correspond with us.
Information Collected via Technology
In an effort to improve the quality of the Service, we may track information using cookies or small text files provided to us by your browser when you view our Site, such as the website you came from (the “referring URL”), the type of browser you use, the device from which you connected to the Service, the time and date of access, clickstream to, through, and from our site, and other information that does not personally identify you besides the origin of request (IP Address).
The Company may use both persistent and session cookies to track a user’s preferences when utilizing our services. Persistent cookies shall remain on your computer after you close your session and until you delete them manually. Session cookies expire or get destroyed the moment the browser is closed.
Collection & Use of Personal Data
We collect and process personal data for one or more of the following purposes:
- To provide you with information that you have requested or that we think may be relevant to a subject in which you have demonstrated an interest.
- To ensure the security and safe operation of our websites and underlying business infrastructure.
- To manage any communication between you and us.
Purposes and lawful grounds for processing
We process personal data on the basis of your consent or for certain legitimate uses permitted under the Digital Personal Data Protection Act, 2023, including the following:
- To provide better usability, troubleshooting and site maintenance;
- To understand which parts of the website are visited and how frequently;
- To create your user ID;
- To identify you once you register on our website;
- To contact you and respond to your questions or requests; and
- To provide access to desirable content based on your preferences.
- To process job application and alumni related requests, more details about which are available on corresponding portals of this website.
- As a participant of a competition, to publish your name and corresponding details to make them available to a larger audience on the Internet, where you have consented.
If a new employee joins our organization
- For assisting the recruitment, selection and other associated processes including background verification (BGV) by our authorized vendors.
- For carrying out various employer related activities if you are selected to join the organization and to enable us to ensure that we are compliant with any applicable labour and/or other relevant laws.
Data We Collect & Process
The table below describes the various forms of personal data that we collect through this website and the lawful ground for processing this data. We have processes in place to make sure that only those authorized people who need to access your data can do so.
| Purpose | Category | Data collected | Purpose for collection | Lawful ground | Shared with | Retention |
|---|---|---|---|---|---|---|
| Security | Security information | Technical information, including IP address, as described above. | To protect our websites and infrastructure from cyber-attack or other threats and to report and deal with any illegal acts. | Legitimate use | Internally, forensic and other organizations with which we might contract for this purpose. | As needed for legal compliance |
| Consent Management | Consent records | Consent status, timestamps | To manage, verify, and audit user consent for data processing | Legal obligation | Data Protection Board of India, auditors | As per DPDP Act & Rules |
| Access & Correction | Personal data | Name, email, contact details | To enable data principals to access, correct and erase their personal data | Data principal rights | Internally | Until request fulfilled or as per legal requirement |
| Data Minimization | Personal data | Only necessary data for the service | To limit data collection to what is strictly required for the stated purpose | Legitimate use | Internally | As needed for service delivery |
| Data Sharing / Disclosure | Shared data | Data shared with third parties / data processors | To fulfil contractual, legal, or regulatory obligations | Legal obligation / consent | Vendors, regulators, law enforcement | As required by law or contract |
| Data Retention & Destruction | Retention records | Data retention logs | To ensure data is retained only as long as necessary and securely destroyed / anonymized | Legal obligation | Internally | As per retention schedule, sectoral laws |
| Breach Notification | Incident records | Breach details, affected data | To notify the Data Protection Board of India and affected individuals in case of a personal data breach | Legal obligation | Data Protection Board of India, affected users | As required by law |
| Training & Awareness | Training logs | Employee training records | To ensure staff are aware of data protection responsibilities | Legitimate use | Internally | For audit readiness, as per policy |
- Category
- Security information
- Data collected
- Technical information, including IP address, as described above.
- Purpose
- To protect our websites and infrastructure from cyber-attack or other threats and to report and deal with any illegal acts.
- Shared with
- Internally, forensic and other organizations with which we might contract for this purpose.
- Retention
- As needed for legal compliance
- Category
- Consent records
- Data collected
- Consent status, timestamps
- Purpose
- To manage, verify, and audit user consent for data processing
- Shared with
- Data Protection Board of India, auditors
- Retention
- As per DPDP Act & Rules
- Category
- Personal data
- Data collected
- Name, email, contact details
- Purpose
- To enable data principals to access, correct and erase their personal data
- Shared with
- Internally
- Retention
- Until request fulfilled or as per legal requirement
- Category
- Personal data
- Data collected
- Only necessary data for the service
- Purpose
- To limit data collection to what is strictly required for the stated purpose
- Shared with
- Internally
- Retention
- As needed for service delivery
- Category
- Shared data
- Data collected
- Data shared with third parties / data processors
- Purpose
- To fulfil contractual, legal, or regulatory obligations
- Shared with
- Vendors, regulators, law enforcement
- Retention
- As required by law or contract
- Category
- Retention records
- Data collected
- Data retention logs
- Purpose
- To ensure data is retained only as long as necessary and securely destroyed / anonymized
- Shared with
- Internally
- Retention
- As per retention schedule, sectoral laws
- Category
- Incident records
- Data collected
- Breach details, affected data
- Purpose
- To notify the Data Protection Board of India and affected individuals in case of a personal data breach
- Shared with
- Data Protection Board of India, affected users
- Retention
- As required by law
- Category
- Training logs
- Data collected
- Employee training records
- Purpose
- To ensure staff are aware of data protection responsibilities
- Shared with
- Internally
- Retention
- For audit readiness, as per policy
Children's Privacy
We do not knowingly collect personal data from any individual under the age of 18 (a “child” under the Digital Personal Data Protection Act, 2023) without verifiable consent from a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from a child without verifiable parental consent, we shall take steps to remove that information from our servers.
Your Rights as a Data Principal
As a data principal under the Digital Personal Data Protection Act, 2023, you have the following rights in respect of the personal data we process about you. To exercise any of these rights, please email privacy@hypersofttechnologies.com or use the information supplied in the Contact us section on this website. To process your request, we will ask you to provide details of identification for verification purposes.
Right to access information
You may request a summary of the personal data we process about you and the processing activities we undertake, along with the identities of other data fiduciaries and data processors with whom your personal data has been shared, together with a description of the data shared.
Right to correction and erasure
You may request that we correct inaccurate or misleading personal data, complete incomplete data, update your data, and erase personal data that is no longer necessary for the purpose for which it was processed, unless retention is required under applicable law.
Right of grievance redressal
You have the right to a readily available means of grievance redressal in respect of any act or omission regarding our processing of your personal data or the exercise of your rights. You may contact our Grievance Officer (details in the Grievance Redressal section), and we will respond within the timelines prescribed under applicable law.
Right to nominate
You may nominate another individual to exercise your rights under the Digital Personal Data Protection Act, 2023 in the event of your death or incapacity.
Additional rights for EU, UK and California residents
If you are (i) a citizen of, or residing and located in, the European Union or the United Kingdom, or (ii) a consumer who is a California state resident, you may have the following additional rights in respect of the personal data we hold. These rights do not apply to IP addresses captured for security reasons, but apply to personal information collected in any subsequent correspondence.
The right to be informed
As a data controller, we are obliged to provide clear and transparent information about our data processing activities. This is provided by this privacy policy and any related communications we may send you.
The right of access
You may request a copy of the personal data we hold about you if relevant. Once we verify your identity and, if relevant, the authority of any third-party requestor, we will provide access to the personal data we hold about you as well as the following information wherever relevant:
- The purposes of the processing
- The categories of personal data concerned
- The recipients to whom the personal data has been disclosed
- The retention period or envisioned retention period for that personal data
- The source of the personal data if collected from other sources
If there are exceptional circumstances that mean we can refuse to provide the information, we will explain them. If requests are frivolous or vexatious, we reserve the right to refuse them. If addressing the requests is likely to take time or incur expenses, which you may have to meet, in any specific case, we will inform you.
The right to rectification
When you believe we hold inaccurate or incomplete personal information about you, you may exercise your right to correct or complete this data. This may be used with the right to restrict processing to make sure that incorrect / incomplete information is not processed until it is corrected.
The right to erasure (the 'right to be forgotten')
Where no overriding legal basis or legitimate reason continues to exist for processing personal data, you may request that we delete the personal data. We will take all reasonable steps to ensure erasure.
The right to restrict processing
You may ask us to stop processing your personal data. We will still hold the data but will not process it any further. This right is an alternative to the right to erasure. If one of the following conditions applies you may exercise the right to restrict processing:
- The accuracy of the personal data is contested.
- Processing of the personal data is unlawful.
- We no longer need the personal data for processing, but the personal data is to be retained for a legal purpose.
- The right to object has been exercised and processing is restricted pending a decision on the status of the processing.
The right to data portability
You may request your set of personal data be transferred to another controller or processor, provided in a commonly used and machine-readable format. This right is only available if the original processing was based on consent, the processing is by automated means, the processing is based on the fulfilment of a contractual obligation, and if transmitting the data to a new controller or processor is technically feasible.
The right to object
You have the right to object to our processing of your data where:
- Processing is for the purpose of direct marketing;
- Processing is for the purposes of scientific or historic research; or
- Processing involves automated decision-making and profiling;
- Processing is based on legitimate interests of others.
Data Protection, Retention & Transfer
How we protect information
To safeguard your personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we have implemented reasonable security practices and procedures, including administrative, physical and technical measures such as pseudonymization, firewalls and secure transmission channels, in line with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.
Access, correction & accuracy
You can request access to a copy of the personal data which we hold about you, and you can make a request to correct, complete, update or erase any of your personal data. You may submit your request in writing or via email to our Data Protection / Grievance Officer. We generally rely on personal data provided by you (or your authorised representative), so please update us if there are changes to your personal data.
Data retention
Hypersoft Technologies Limited retains personal data only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, or as required or permitted under applicable Indian law (including record-retention obligations under labour, tax and company law). When personal data is no longer required to be retained, we securely delete, destroy or anonymise it.
International data transfer
As a company headquartered in India, we primarily process personal data in India and may transfer it to, or access it from, other countries in the course of providing our services. Any transfer of personal data outside India is carried out in accordance with the Digital Personal Data Protection Act, 2023, and will not be made to any country or territory that is restricted for such transfers by the Central Government of India.
Where we receive personal data from the European Union / EEA, the United Kingdom (including Gibraltar) or Switzerland, we ensure such transfers are carried out in accordance with applicable data protection laws and rely on recognised and lawful transfer mechanisms, including Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework, together with appropriate technical and organizational safeguards. In the event of any inconsistency between this Privacy Policy and applicable data protection law, the relevant law shall prevail.
Grievance Redressal
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (and rules thereunder), we have appointed a Grievance Officer to address your questions, concerns or complaints regarding this Privacy Policy or our processing of your personal data. We will acknowledge and seek to resolve grievances within the timelines prescribed under applicable law.
Grievance Officer
[Grievance Officer Name]
Hypersoft Technologies Limited
[Registered office address], India
If your grievance is not resolved to your satisfaction, you may have the right to register a complaint with the Data Protection Board of India, in accordance with the Digital Personal Data Protection Act, 2023.
Changes & External Links
External components and links to other websites
As part of our Site functionality, we have integrated third-party plug-ins or components and provided links to external websites. We are not responsible for the privacy practices of those external sources or websites. This Privacy Policy applies solely to the information collected by us through our Site. We encourage our users to read the privacy statements of other websites before proceeding to use them.
Governing law
This Privacy Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, and rules made thereunder. The courts at [City], India shall have exclusive jurisdiction over any dispute arising in relation to this Privacy Policy.
Changes to our Privacy Policy
The Company reserves the right to change this policy and our Terms of Service at any time. We will notify you if there are significant changes to our Privacy Policy by placing a prominent notice on our Site. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. You should periodically check the Site and this privacy page for updates.
Questions about your data?
You may submit inquiries or complaints regarding the processing or transfer of your personal data by contacting our Data Protection / Grievance Officer. We will investigate and seek to resolve such requests in a timely manner in accordance with applicable data protection laws.
