Effective 1 September 2026 · Version 1.0
Privacy policy
Redcubical Systems Private Limited is the data controller for personal data collected through this website and through our enquiry, client, recruitment and supplier relationships. This notice explains what we collect, why, how long we keep it, who we share it with, and how to exercise your rights under the UK and EU GDPR and under India’s Digital Personal Data Protection Act 2023.
- Controller: Redcubical Systems Private Limited, Dehradun, India
- Privacy contact: nitesh@redcubical.com
- Rights covered under both GDPR and the DPDP Act 2023
- Transfers to India rely on standard contractual clauses
Section 1
Who we are and how to reach us
Who is responsible for your personal data?
Redcubical Systems Private Limited, a private limited company incorporated in India in October 2022 with its registered office at Dev Heights, First Floor, Aman Vihar, Sahastradhara Road, Dehradun, Uttarakhand 248001, India, is the data controller for the processing described in this notice. Where we process personal data inside a client system under a services agreement, the client is the controller and we act as a processor on their documented instructions.
This notice applies to: visitors to https://www.redcubical.com; people who contact us by email, telephone, the enquiry form or a professional network; representatives of our clients and prospective clients; candidates who apply for a role; and contacts at our suppliers and subcontracted service providers.
It does not apply to personal data held inside a client platform we build or operate on that client’s behalf. In that situation we are a processor, our processing is governed by the data processing agreement with that client, and any request about that data should be directed to the client as controller. If you contact us about such data we will tell you promptly and, where we lawfully can, pass your request on.
Our two roles, stated plainly. As a data fiduciary and controller we decide how our own website, marketing, recruitment and supplier data is handled. As a data processor we handle client data only as instructed. Our position under Indian law is set out in more detail on our DPDP Act compliance page.
Controller details
- Controller
- Redcubical Systems Private Limited
- Registered office
- Dev Heights, First Floor, Aman Vihar, Sahastradhara Road, Dehradun, Uttarakhand 248001, India
- Company registration
- Corporate Identity Number [Company to confirm before publication]
- Incorporated
- October 2022, India
- Privacy contact
- nitesh@redcubical.com
- Data protection officer
- Name and appointment date [Company to confirm before publication]
- Grievance officer
- See grievance officer page
- Telephone
- +91 90687 14658
- Effective date
- 1 September 2026
- Version
- 1.0
- UK or EU representative
- Appointment under Article 27 [Company to confirm before publication]
Section 2
What personal data we collect, and from whom
We collect the minimum needed for each relationship. The table below is organised by the kind of person whose data we hold, because that is how you are likely to read it.
| Who you are | What we collect | Where it comes from | Is it required |
|---|---|---|---|
| Website visitor | IP address, approximate location derived from it, browser and device type, pages viewed, referring URL, timestamps, and analytics identifiers where analytics tags load | Automatically from your browser, our hosting provider logs, and Google Tag Manager containers | Server logs are necessary to run and secure the site. Analytics is optional |
| Enquirer or prospective client | Name, employer, job title, work email, telephone number, country, budget and timing indications, and the content of your enquiry including attachments | Directly from you, through the enquiry form, email, telephone or a professional network | Name, employer and email are required to reply. Everything else is optional |
| Client contact | Business contact details, role, signatory and authorisation details, engagement correspondence, meeting notes, credentials issued to you, invoicing contacts | Directly from you and from your colleagues during an engagement | Required to perform the contract and to invoice correctly |
| Candidate | Name, contact details, CV content, work and education history, portfolio and code links, interview notes and exercise submissions, right-to-work and identity confirmation, referee details, salary expectations | Directly from you, from referees you nominate, and from a background verification provider at offer stage with your consent | CV and contact details are required. Referees and verification apply only at offer stage |
| Supplier or partner contact | Business contact details, role, contract and onboarding documentation, bank and tax details where you invoice us, and due-diligence responses | Directly from you, and from public registers where we verify an entity | Required to contract with and pay you |
| Complainant or data subject making a request | Your identity and contact details, the substance of the complaint or request, correspondence, and any identity evidence you provide | Directly from you, or from a regulator forwarding a complaint | Required to investigate and to respond to you |
We do not knowingly collect special category data under Article 9 UK or EU GDPR, and we do not ask for it. If you send us health, religious, political, biometric or similar information in free text, we will not use it and will delete it from our records where it is not needed. We do not carry out profiling or automated decision-making that produces legal effects, and we do not sell personal data or share it for cross-context behavioural advertising.
Section 3
Why we use it, and our lawful basis
Each purpose has one primary lawful basis. Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it.
What lawful bases do you rely on?
We rely on four lawful bases: performance of a contract, our legitimate interests, your consent, and compliance with a legal obligation. Under India’s DPDP Act 2023 the equivalent grounds are consent and the specified legitimate uses. Marketing to a person at a business email address relies on legitimate interests with an unconditional opt-out in every message.
| Purpose | Data used | Lawful basis (UK and EU GDPR) | DPDP Act 2023 ground |
|---|---|---|---|
| Responding to an enquiry and preparing a proposal | Enquirer and prospective client data | Legitimate interests, and steps preparatory to a contract at your request | Legitimate use: you voluntarily provided the data for this purpose |
| Delivering, supporting and invoicing an engagement | Client contact data, correspondence, access records | Performance of a contract | Performance of contract, and consent given at engagement |
| Operating, securing and debugging this website | Server logs, IP address, device and request data | Legitimate interests in availability, security and abuse prevention | Legitimate use: security and prevention of misuse |
| Measuring how the site is used | Analytics identifiers, page and event data | Consent, where required in your jurisdiction | Consent |
| Sending business information you asked for | Business contact details and stated interests | Consent, or legitimate interests for existing business contacts | Consent, withdrawable at any time |
| Assessing a job application | Candidate data, exercise submissions, interview notes | Legitimate interests in recruiting, and steps preparatory to an employment contract | Legitimate use: employment purposes |
| Background and right-to-work verification at offer stage | Identity, education and employment confirmation where lawful | Legal obligation and legitimate interests, with your consent to the check itself | Consent, and employment purposes |
| Managing suppliers and paying them | Supplier contact, contract, bank and tax data | Performance of a contract and legal obligation | Performance of contract and legal obligation |
| Meeting tax, accounting and statutory audit duties | Contract, invoice and payment records | Legal obligation under Indian law | Legal obligation |
| Handling complaints, requests, disputes and legal claims | Correspondence, engagement records, identity evidence | Legal obligation and legitimate interests in establishing or defending legal claims | Legitimate use: enforcement of legal rights and claims |
Where consent is the basis you may withdraw it at any time, without giving a reason, by emailing our privacy contact or using the unsubscribe link. Withdrawal does not affect processing already carried out lawfully, and it does not affect processing we must continue for a legal obligation such as retaining an invoice.
Cookies, tags and analytics
This site is static HTML and sets no cookies of its own for advertising or profiling. It functions fully with all cookies blocked.
We deploy Google Tag Manager (container ID GTM-KJ9GRFS2). Tag Manager is a container: it loads other tags, which at present are limited to web analytics. Once loaded, those tags may set first-party cookies or local storage identifiers to distinguish sessions and measure page views, referral sources and simple events such as clicking an email link.
Non-essential tags load only where consent has been given or is not required in your jurisdiction. You can block them entirely with a browser setting, an extension, or your operating system tracking controls, and nothing on this site will stop working. Google acts as our processor for analytics data under its data processing terms; Google’s own notice explains its role in more detail.
We do not use advertising pixels, remarketing tags, session recording, heat mapping or cross-site identity graphs. If that changes, this section changes first and the version history at the foot of this page will say so.
Section 4
How long we keep it, who receives it, and where it goes
| Record | Retention period | Why that period |
|---|---|---|
| Server and security logs | 90 days rolling, then deleted | Long enough to investigate an incident, short enough to limit exposure |
| Analytics data | 14 months, then aggregated or deleted | Allows year-on-year comparison without indefinite retention |
| Enquiries that did not become engagements | 24 months from last contact | Sales cycles in our market commonly run 6 to 18 months |
| Marketing consent and preference records | 3 years from withdrawal or last engagement | Evidence that we honoured your choice |
| Client contracts, statements of work and invoices | 8 years after the engagement ends | Indian tax, companies-law and statutory audit requirements |
| Engagement correspondence and delivery records | 3 years after the engagement ends | Warranty, dispute and reference window |
| Client system access and audit logs | 12 months, or as the client contract specifies | Security investigation, subject to the client instruction |
| Unsuccessful candidate records | 12 months from the decision, or 6 months on request | Allows us to reconsider you, and to answer a discrimination claim |
| Successful candidate records | Merged into the employment file, per employment law | Statutory employment record keeping |
| Supplier records and payments | 8 years after the relationship ends | Tax and audit requirements |
| Data subject requests and complaints | 3 years from closure | Demonstrating compliance to a regulator |
| Backups containing any of the above | Up to 35 days beyond the primary deletion date | Backup rotation cannot be surgically edited |
Where a record is subject to a legal hold, a live dispute or a regulatory investigation, retention is extended until the matter closes, and we will tell you if that affects a deletion request you have made. At the end of a period, records are deleted or irreversibly anonymised. Anonymised aggregate statistics, such as how many enquiries came from a market, may be kept indefinitely because they are no longer personal data.
Who receives your personal data
We share personal data with a small set of processors, each under a written contract containing confidentiality, security and deletion obligations, and each restricted to processing on our instructions. Categories of recipient:
- Cloud hosting and infrastructure providers for this site and our internal systems, in the regions stated in the transfers section below.
- Business productivity and email providers where our correspondence with you is stored.
- Analytics and tag management, currently Google, for website measurement.
- The enquiry form handler disclosed on our contact page.
- Accounting, payroll, banking and tax advisers for invoicing and statutory filing.
- Background verification providers at candidate offer stage only, with consent.
- Professional advisers, including lawyers and auditors, where we need advice or must be audited. Our statutory auditor is [Company to confirm before publication].
- Insurers and brokers in connection with a claim. Our professional indemnity and cyber insurer is [Company to confirm before publication].
- Regulators, courts and law enforcement where we are legally required to disclose, and we will tell you unless prohibited from doing so.
A current, named subprocessor list with locations is available to clients on request as part of a security review. We do not sell personal data, we do not share it for advertising, and we do not transfer it to a purchaser except as part of a corporate transaction, in which case the recipient would be bound by this notice until it published its own.
Section 5
Your rights, and how to exercise them
You have rights under the UK and EU GDPR and, separately, as a Data Principal under India’s DPDP Act 2023. The table sets out both, what each one means in practice here, and how to use it.
How do I exercise a privacy right?
Email nitesh@redcubical.com with "data request" in the subject line and tell us which right you are exercising. We acknowledge within 48 hours and respond substantively within 30 days, which is inside the GDPR one-month deadline. There is no charge. We may ask for proof of identity where we cannot otherwise be confident who you are.
| Right | What it means here | Applies under | Our response time |
|---|---|---|---|
| Access | A copy of the personal data we hold about you, with the purposes, recipients, retention and sources | GDPR Article 15; DPDP Section 11 | 30 days |
| Rectification and correction | Correction of inaccurate data and completion of incomplete data, including in records held by our processors | GDPR Article 16; DPDP Section 12 | 30 days, usually within 7 |
| Erasure | Deletion where the data is no longer needed, consent is withdrawn, or processing was unlawful. Statutory retention such as invoices can override this | GDPR Article 17; DPDP Section 12 | 30 days |
| Restriction | We pause processing while a dispute about accuracy or lawfulness is resolved | GDPR Article 18 | 30 days |
| Objection | You can object to processing based on legitimate interests, and object to direct marketing at any time with immediate effect | GDPR Article 21 | Marketing stops within 3 days |
| Portability | Data you gave us, in a structured machine-readable format, where processing is by consent or contract and is automated | GDPR Article 20 | 30 days |
| Withdraw consent | Withdraw at any time, as easily as it was given, with no detriment and no explanation required | GDPR Article 7(3); DPDP Section 6(4) | Actioned within 3 days |
| Nomination | Nominate another person to exercise your rights on your behalf in the event of death or incapacity | DPDP Section 14 | Recorded within 30 days |
| Grievance redressal | A readily available means of complaint to us before approaching the regulator, handled by our grievance officer | DPDP Section 13 | 30 days, and 15 days for IT Rules grievances |
| Complaint to a regulator | Complain to a supervisory authority at any time, whether or not you came to us first | GDPR Article 77; DPDP Chapter V | Set by the regulator |
| Human review of automated decisions | Not applicable. We do not make solely automated decisions with legal or similarly significant effects | GDPR Article 22 | Not applicable |
If we cannot act on a request we will tell you why and what your options are, including complaining to a regulator. If a request is manifestly unfounded or excessive, particularly a repetitive one, we may charge a reasonable fee or decline, and we will tell you before doing either. Where you make a request about data we hold as a processor for a client, we will identify the client and pass your request on, but the client decides the response.
Complaint routes
- Us first, if you are willing. Our grievance officer, described on the grievance officer page, is the fastest route and we would rather fix a problem than have it escalated.
- United Kingdom. The Information Commissioner’s Office, at ico.org.uk, by telephone or through its online complaint process. Our ICO registration status is [Company to confirm before publication].
- European Union and EEA. Your national data protection authority, or the authority in the member state where you live, work or where the issue occurred.
- India. The Data Protection Board of India, once constituted and operating under the DPDP Act 2023. Under the Act you must generally exhaust our grievance process before approaching the Board.
- Other jurisdictions. Contact your local privacy regulator. Tell us which one and we will engage with them directly.
Section 6
Children, breaches and changes to this notice
Children’s data
This is a business-to-business website and our services are not directed at children. We do not knowingly collect personal data from anyone under 18 through this site, and we have no reason to.
Under Section 9 of the DPDP Act 2023, processing a child’s personal data in India requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. We do none of those things.
Where a client platform we build processes children’s data, for example a paediatric clinical record, verifiable consent is the client’s obligation as controller. We will support it technically and will say so in the data processing agreement rather than leaving it ambiguous.
If you believe a child has given us personal data, tell us at nitesh@redcubical.com and we will delete it without asking for justification.
| Version | Effective | Change |
|---|---|---|
| 1.0 | 1 September 2026 | First published version. Adopted by the company following internal review. |
Every entry marked [Company to confirm before publication] must be completed before publication. Those markers are deliberately visible so an incomplete notice cannot go live unnoticed.
Answers
Privacy questions
Who is the data controller for personal data collected on this website?
Redcubical Systems Private Limited, at Dev Heights, First Floor, Aman Vihar, Sahastradhara Road, Dehradun, Uttarakhand 248001, India, is the data controller for personal data collected through this website and through our marketing, recruitment and supplier activity. For personal data we process inside a client platform under a services contract, the client is the controller and we act as processor on their written instructions.
How do I make a data subject access request?
Email nitesh@redcubical.com with the words "data request" in the subject line, tell us which right you are exercising, and give us enough information to locate your records. We acknowledge within 48 hours and respond substantively within 30 days. There is no charge unless a request is manifestly excessive, in which case we tell you the fee before doing the work.
Do you transfer personal data outside the UK or the EEA?
Yes. We are established in India, so any personal data you send us is processed in India, which has no UK or EU adequacy decision. Those transfers rely on the UK International Data Transfer Addendum or the EU standard contractual clauses, supported by a transfer risk assessment, encryption in transit and at rest, and access controls limiting who can see the data.
What cookies does this website set?
The site itself sets no advertising or profiling cookies and works fully without them. Google Tag Manager is present and loads analytics tags, which may set first-party analytics cookies and identifiers once loaded. Those are non-essential and are only loaded where consent has been given or is not required in your jurisdiction. Blocking them does not affect any function of the site.
How long do you keep enquiry and recruitment data?
Enquiries that do not become engagements are kept for 24 months, then deleted. Candidate applications are kept for 12 months from the final decision, or 6 months where you ask us to keep nothing further. Client contract records are kept for 8 years after the engagement ends to meet Indian tax and statutory audit requirements. Full detail is in the retention table on this page.
Which regulator do I complain to if I am unhappy with your response?
In the UK, the Information Commissioner’s Office. In the EU or EEA, your national data protection authority. In India, the Data Protection Board of India once it is constituted and operating under the DPDP Act 2023. You can complain to a regulator at any time, and we would ask you to raise it with our grievance officer first so we have a chance to fix it.
A privacy request, or a security questionnaire
Both go to the same place and both get a human answer. Requests are acknowledged within 48 hours; questionnaires take three to five business days because an engineer completes them.