Engineering hubs in Dehradun & Bengaluru · Delivering across 10 countries

nitesh@redcubical.com +91 90687 14658

REDCUBICALSYSTEMS

Effective 1 September 2026 · Version 1.0

Privacy policy

Redcubical Systems Private Limited is the data controller for personal data collected through this website and through our enquiry, client, recruitment and supplier relationships. This notice explains what we collect, why, how long we keep it, who we share it with, and how to exercise your rights under the UK and EU GDPR and under India’s Digital Personal Data Protection Act 2023.

  • Controller: Redcubical Systems Private Limited, Dehradun, India
  • Privacy contact: nitesh@redcubical.com
  • Rights covered under both GDPR and the DPDP Act 2023
  • Transfers to India rely on standard contractual clauses

Section 1

Who we are and how to reach us

Who is responsible for your personal data?

Redcubical Systems Private Limited, a private limited company incorporated in India in October 2022 with its registered office at Dev Heights, First Floor, Aman Vihar, Sahastradhara Road, Dehradun, Uttarakhand 248001, India, is the data controller for the processing described in this notice. Where we process personal data inside a client system under a services agreement, the client is the controller and we act as a processor on their documented instructions.

This notice applies to: visitors to https://www.redcubical.com; people who contact us by email, telephone, the enquiry form or a professional network; representatives of our clients and prospective clients; candidates who apply for a role; and contacts at our suppliers and subcontracted service providers.

It does not apply to personal data held inside a client platform we build or operate on that client’s behalf. In that situation we are a processor, our processing is governed by the data processing agreement with that client, and any request about that data should be directed to the client as controller. If you contact us about such data we will tell you promptly and, where we lawfully can, pass your request on.

Our two roles, stated plainly. As a data fiduciary and controller we decide how our own website, marketing, recruitment and supplier data is handled. As a data processor we handle client data only as instructed. Our position under Indian law is set out in more detail on our DPDP Act compliance page.

Controller details

Controller
Redcubical Systems Private Limited
Registered office
Dev Heights, First Floor, Aman Vihar, Sahastradhara Road, Dehradun, Uttarakhand 248001, India
Company registration
Corporate Identity Number [Company to confirm before publication]
Incorporated
October 2022, India
Privacy contact
nitesh@redcubical.com
Data protection officer
Name and appointment date [Company to confirm before publication]
Effective date
1 September 2026
Version
1.0
UK or EU representative
Appointment under Article 27 [Company to confirm before publication]

Section 2

What personal data we collect, and from whom

We collect the minimum needed for each relationship. The table below is organised by the kind of person whose data we hold, because that is how you are likely to read it.

Categories of personal data by data subject group
Who you areWhat we collectWhere it comes fromIs it required
Website visitorIP address, approximate location derived from it, browser and device type, pages viewed, referring URL, timestamps, and analytics identifiers where analytics tags loadAutomatically from your browser, our hosting provider logs, and Google Tag Manager containersServer logs are necessary to run and secure the site. Analytics is optional
Enquirer or prospective clientName, employer, job title, work email, telephone number, country, budget and timing indications, and the content of your enquiry including attachmentsDirectly from you, through the enquiry form, email, telephone or a professional networkName, employer and email are required to reply. Everything else is optional
Client contactBusiness contact details, role, signatory and authorisation details, engagement correspondence, meeting notes, credentials issued to you, invoicing contactsDirectly from you and from your colleagues during an engagementRequired to perform the contract and to invoice correctly
CandidateName, contact details, CV content, work and education history, portfolio and code links, interview notes and exercise submissions, right-to-work and identity confirmation, referee details, salary expectationsDirectly from you, from referees you nominate, and from a background verification provider at offer stage with your consentCV and contact details are required. Referees and verification apply only at offer stage
Supplier or partner contactBusiness contact details, role, contract and onboarding documentation, bank and tax details where you invoice us, and due-diligence responsesDirectly from you, and from public registers where we verify an entityRequired to contract with and pay you
Complainant or data subject making a requestYour identity and contact details, the substance of the complaint or request, correspondence, and any identity evidence you provideDirectly from you, or from a regulator forwarding a complaintRequired to investigate and to respond to you

We do not knowingly collect special category data under Article 9 UK or EU GDPR, and we do not ask for it. If you send us health, religious, political, biometric or similar information in free text, we will not use it and will delete it from our records where it is not needed. We do not carry out profiling or automated decision-making that produces legal effects, and we do not sell personal data or share it for cross-context behavioural advertising.

Section 3

Why we use it, and our lawful basis

Each purpose has one primary lawful basis. Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it.

What lawful bases do you rely on?

We rely on four lawful bases: performance of a contract, our legitimate interests, your consent, and compliance with a legal obligation. Under India’s DPDP Act 2023 the equivalent grounds are consent and the specified legitimate uses. Marketing to a person at a business email address relies on legitimate interests with an unconditional opt-out in every message.

Purpose, data used, lawful basis and DPDP ground
PurposeData usedLawful basis (UK and EU GDPR)DPDP Act 2023 ground
Responding to an enquiry and preparing a proposalEnquirer and prospective client dataLegitimate interests, and steps preparatory to a contract at your requestLegitimate use: you voluntarily provided the data for this purpose
Delivering, supporting and invoicing an engagementClient contact data, correspondence, access recordsPerformance of a contractPerformance of contract, and consent given at engagement
Operating, securing and debugging this websiteServer logs, IP address, device and request dataLegitimate interests in availability, security and abuse preventionLegitimate use: security and prevention of misuse
Measuring how the site is usedAnalytics identifiers, page and event dataConsent, where required in your jurisdictionConsent
Sending business information you asked forBusiness contact details and stated interestsConsent, or legitimate interests for existing business contactsConsent, withdrawable at any time
Assessing a job applicationCandidate data, exercise submissions, interview notesLegitimate interests in recruiting, and steps preparatory to an employment contractLegitimate use: employment purposes
Background and right-to-work verification at offer stageIdentity, education and employment confirmation where lawfulLegal obligation and legitimate interests, with your consent to the check itselfConsent, and employment purposes
Managing suppliers and paying themSupplier contact, contract, bank and tax dataPerformance of a contract and legal obligationPerformance of contract and legal obligation
Meeting tax, accounting and statutory audit dutiesContract, invoice and payment recordsLegal obligation under Indian lawLegal obligation
Handling complaints, requests, disputes and legal claimsCorrespondence, engagement records, identity evidenceLegal obligation and legitimate interests in establishing or defending legal claimsLegitimate use: enforcement of legal rights and claims

Where consent is the basis you may withdraw it at any time, without giving a reason, by emailing our privacy contact or using the unsubscribe link. Withdrawal does not affect processing already carried out lawfully, and it does not affect processing we must continue for a legal obligation such as retaining an invoice.

Cookies, tags and analytics

This site is static HTML and sets no cookies of its own for advertising or profiling. It functions fully with all cookies blocked.

We deploy Google Tag Manager (container ID GTM-KJ9GRFS2). Tag Manager is a container: it loads other tags, which at present are limited to web analytics. Once loaded, those tags may set first-party cookies or local storage identifiers to distinguish sessions and measure page views, referral sources and simple events such as clicking an email link.

Non-essential tags load only where consent has been given or is not required in your jurisdiction. You can block them entirely with a browser setting, an extension, or your operating system tracking controls, and nothing on this site will stop working. Google acts as our processor for analytics data under its data processing terms; Google’s own notice explains its role in more detail.

We do not use advertising pixels, remarketing tags, session recording, heat mapping or cross-site identity graphs. If that changes, this section changes first and the version history at the foot of this page will say so.

Section 4

How long we keep it, who receives it, and where it goes

Retention periods
RecordRetention periodWhy that period
Server and security logs90 days rolling, then deletedLong enough to investigate an incident, short enough to limit exposure
Analytics data14 months, then aggregated or deletedAllows year-on-year comparison without indefinite retention
Enquiries that did not become engagements24 months from last contactSales cycles in our market commonly run 6 to 18 months
Marketing consent and preference records3 years from withdrawal or last engagementEvidence that we honoured your choice
Client contracts, statements of work and invoices8 years after the engagement endsIndian tax, companies-law and statutory audit requirements
Engagement correspondence and delivery records3 years after the engagement endsWarranty, dispute and reference window
Client system access and audit logs12 months, or as the client contract specifiesSecurity investigation, subject to the client instruction
Unsuccessful candidate records12 months from the decision, or 6 months on requestAllows us to reconsider you, and to answer a discrimination claim
Successful candidate recordsMerged into the employment file, per employment lawStatutory employment record keeping
Supplier records and payments8 years after the relationship endsTax and audit requirements
Data subject requests and complaints3 years from closureDemonstrating compliance to a regulator
Backups containing any of the aboveUp to 35 days beyond the primary deletion dateBackup rotation cannot be surgically edited

Where a record is subject to a legal hold, a live dispute or a regulatory investigation, retention is extended until the matter closes, and we will tell you if that affects a deletion request you have made. At the end of a period, records are deleted or irreversibly anonymised. Anonymised aggregate statistics, such as how many enquiries came from a market, may be kept indefinitely because they are no longer personal data.

Who receives your personal data

We share personal data with a small set of processors, each under a written contract containing confidentiality, security and deletion obligations, and each restricted to processing on our instructions. Categories of recipient:

  • Cloud hosting and infrastructure providers for this site and our internal systems, in the regions stated in the transfers section below.
  • Business productivity and email providers where our correspondence with you is stored.
  • Analytics and tag management, currently Google, for website measurement.
  • The enquiry form handler disclosed on our contact page.
  • Accounting, payroll, banking and tax advisers for invoicing and statutory filing.
  • Background verification providers at candidate offer stage only, with consent.
  • Professional advisers, including lawyers and auditors, where we need advice or must be audited. Our statutory auditor is [Company to confirm before publication].
  • Insurers and brokers in connection with a claim. Our professional indemnity and cyber insurer is [Company to confirm before publication].
  • Regulators, courts and law enforcement where we are legally required to disclose, and we will tell you unless prohibited from doing so.

A current, named subprocessor list with locations is available to clients on request as part of a security review. We do not sell personal data, we do not share it for advertising, and we do not transfer it to a purchaser except as part of a corporate transaction, in which case the recipient would be bound by this notice until it published its own.

Section 5

Your rights, and how to exercise them

You have rights under the UK and EU GDPR and, separately, as a Data Principal under India’s DPDP Act 2023. The table sets out both, what each one means in practice here, and how to use it.

How do I exercise a privacy right?

Email nitesh@redcubical.com with "data request" in the subject line and tell us which right you are exercising. We acknowledge within 48 hours and respond substantively within 30 days, which is inside the GDPR one-month deadline. There is no charge. We may ask for proof of identity where we cannot otherwise be confident who you are.

Rights, scope and how to use them
RightWhat it means hereApplies underOur response time
AccessA copy of the personal data we hold about you, with the purposes, recipients, retention and sourcesGDPR Article 15; DPDP Section 1130 days
Rectification and correctionCorrection of inaccurate data and completion of incomplete data, including in records held by our processorsGDPR Article 16; DPDP Section 1230 days, usually within 7
ErasureDeletion where the data is no longer needed, consent is withdrawn, or processing was unlawful. Statutory retention such as invoices can override thisGDPR Article 17; DPDP Section 1230 days
RestrictionWe pause processing while a dispute about accuracy or lawfulness is resolvedGDPR Article 1830 days
ObjectionYou can object to processing based on legitimate interests, and object to direct marketing at any time with immediate effectGDPR Article 21Marketing stops within 3 days
PortabilityData you gave us, in a structured machine-readable format, where processing is by consent or contract and is automatedGDPR Article 2030 days
Withdraw consentWithdraw at any time, as easily as it was given, with no detriment and no explanation requiredGDPR Article 7(3); DPDP Section 6(4)Actioned within 3 days
NominationNominate another person to exercise your rights on your behalf in the event of death or incapacityDPDP Section 14Recorded within 30 days
Grievance redressalA readily available means of complaint to us before approaching the regulator, handled by our grievance officerDPDP Section 1330 days, and 15 days for IT Rules grievances
Complaint to a regulatorComplain to a supervisory authority at any time, whether or not you came to us firstGDPR Article 77; DPDP Chapter VSet by the regulator
Human review of automated decisionsNot applicable. We do not make solely automated decisions with legal or similarly significant effectsGDPR Article 22Not applicable

If we cannot act on a request we will tell you why and what your options are, including complaining to a regulator. If a request is manifestly unfounded or excessive, particularly a repetitive one, we may charge a reasonable fee or decline, and we will tell you before doing either. Where you make a request about data we hold as a processor for a client, we will identify the client and pass your request on, but the client decides the response.

Complaint routes

  • Us first, if you are willing. Our grievance officer, described on the grievance officer page, is the fastest route and we would rather fix a problem than have it escalated.
  • United Kingdom. The Information Commissioner’s Office, at ico.org.uk, by telephone or through its online complaint process. Our ICO registration status is [Company to confirm before publication].
  • European Union and EEA. Your national data protection authority, or the authority in the member state where you live, work or where the issue occurred.
  • India. The Data Protection Board of India, once constituted and operating under the DPDP Act 2023. Under the Act you must generally exhaust our grievance process before approaching the Board.
  • Other jurisdictions. Contact your local privacy regulator. Tell us which one and we will engage with them directly.

Section 6

Children, breaches and changes to this notice

Children’s data

This is a business-to-business website and our services are not directed at children. We do not knowingly collect personal data from anyone under 18 through this site, and we have no reason to.

Under Section 9 of the DPDP Act 2023, processing a child’s personal data in India requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. We do none of those things.

Where a client platform we build processes children’s data, for example a paediatric clinical record, verifiable consent is the client’s obligation as controller. We will support it technically and will say so in the data processing agreement rather than leaving it ambiguous.

If you believe a child has given us personal data, tell us at nitesh@redcubical.com and we will delete it without asking for justification.

Version history
VersionEffectiveChange
1.01 September 2026First published version. Adopted by the company following internal review.

Every entry marked [Company to confirm before publication] must be completed before publication. Those markers are deliberately visible so an incomplete notice cannot go live unnoticed.

Answers

Privacy questions

Who is the data controller for personal data collected on this website?

Redcubical Systems Private Limited, at Dev Heights, First Floor, Aman Vihar, Sahastradhara Road, Dehradun, Uttarakhand 248001, India, is the data controller for personal data collected through this website and through our marketing, recruitment and supplier activity. For personal data we process inside a client platform under a services contract, the client is the controller and we act as processor on their written instructions.

How do I make a data subject access request?

Email nitesh@redcubical.com with the words "data request" in the subject line, tell us which right you are exercising, and give us enough information to locate your records. We acknowledge within 48 hours and respond substantively within 30 days. There is no charge unless a request is manifestly excessive, in which case we tell you the fee before doing the work.

Do you transfer personal data outside the UK or the EEA?

Yes. We are established in India, so any personal data you send us is processed in India, which has no UK or EU adequacy decision. Those transfers rely on the UK International Data Transfer Addendum or the EU standard contractual clauses, supported by a transfer risk assessment, encryption in transit and at rest, and access controls limiting who can see the data.

What cookies does this website set?

The site itself sets no advertising or profiling cookies and works fully without them. Google Tag Manager is present and loads analytics tags, which may set first-party analytics cookies and identifiers once loaded. Those are non-essential and are only loaded where consent has been given or is not required in your jurisdiction. Blocking them does not affect any function of the site.

How long do you keep enquiry and recruitment data?

Enquiries that do not become engagements are kept for 24 months, then deleted. Candidate applications are kept for 12 months from the final decision, or 6 months where you ask us to keep nothing further. Client contract records are kept for 8 years after the engagement ends to meet Indian tax and statutory audit requirements. Full detail is in the retention table on this page.

Which regulator do I complain to if I am unhappy with your response?

In the UK, the Information Commissioner’s Office. In the EU or EEA, your national data protection authority. In India, the Data Protection Board of India once it is constituted and operating under the DPDP Act 2023. You can complain to a regulator at any time, and we would ask you to raise it with our grievance officer first so we have a chance to fix it.

A privacy request, or a security questionnaire

Both go to the same place and both get a human answer. Requests are acknowledged within 48 hours; questionnaires take three to five business days because an engineer completes them.