PRIVACY POLICY
Last Updated: January 25, 2026
Udvas Bhattacharya (operating through Udofera Consultancy Private Limited) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website and services.
Quick Summary: We collect minimal data (name, email, inquiry details) through forms. We use Google Analytics with your consent. Your data stays in India/EU servers. You have full rights to access, delete, or correct your information.
1. WHO WE ARE
Data Controller: Udofera Consultancy Private Limited
Registered Address: B40/1, Kamdahari Narkel Bagan, Kolkata - 700084, West Bengal, India
CIN Number: U62020WB2025PTC283790
GSTIN: 19AADCU9728M1ZI
Director: Udvas Bhattacharya
Contact Email: contact@udvasbhattacharya.com
Phone: +91 81000 90308
EU Representative Status
Under GDPR Article 27(2), we are currently exempt from appointing an EU representative as we:
- Are an enterprise based outside the EU
- Process limited personal data on an occasional basis
- Do not engage in large-scale processing of special categories of data
- Pose minimal risk to the rights and freedoms of data subjects
If our data processing activities expand, we will appoint an EU representative as required by law.
2. WHAT INFORMATION WE COLLECT
Information You Provide Directly
We collect personal information that you voluntarily provide when you:
- Contact us via forms: Name, email address, phone number (optional), message content, inquiry type
- Apply for UB Audit: Name, email, professional status, biggest challenge/hurdle, preferred cohort, commitment acknowledgment
- Request web hosting: Business name, contact details, project requirements, timeline, referral source
- Join eyewear waitlist: Email address, name (optional), lens interest preference
Information Collected Automatically
Google Analytics (with your consent):
- IP address (anonymized)
- Browser type and version
- Device type (desktop, mobile, tablet)
- Pages visited and time spent
- Referring website
- Geographic location (city-level only)
Third-Party Embeds
Instagram Content: We embed Instagram posts on our UB Audit page. When you view these embeds, Instagram may collect data according to their privacy policy: Instagram Privacy Policy
What We Do NOT Collect
- ❌ Credit card or payment information (handled externally by PayPal/payment processors)
- ❌ Social Security numbers, government IDs, or sensitive personal data
- ❌ Health information or medical records
- ❌ Passwords or login credentials (we have no user accounts)
- ❌ Racial, ethnic, political, or religious information
3. HOW WE USE YOUR INFORMATION
Legal Bases for Processing (GDPR Article 6)
We process your data based on:
- Consent: You explicitly consent when submitting forms or accepting cookies
- Contract Performance: Necessary to provide services you've requested (hosting, UB Audit)
- Legitimate Interest: Website analytics to improve user experience (with your consent via cookies)
Specific Uses
- Respond to inquiries: Answer your questions via email within 24-48 hours
- Process applications: Review UB Audit applications and send acceptance/rejection notifications
- Send waitlist updates: Notify you when wooden eyewear pre-orders open (Q3-Q4 2026)
- Improve website: Analyze traffic patterns to fix bugs and enhance navigation
- Send administrative updates: Policy changes, service interruptions (non-marketing)
What We Will NEVER Do
- ❌ Sell your data to third parties
- ❌ Send unsolicited marketing emails (unless you opt-in to our newsletter - feature not yet active)
- ❌ Share your information with advertisers
- ❌ Use your data for purposes other than those stated here
4. HOW WE STORE & PROTECT YOUR DATA
Data Storage & Processing
Form Submissions:
- Processed via: Google Apps Script (automated email routing)
- Stored in: Google Sheets (within our Google Workspace Pro account)
- Data location: EU and US data centers (Google's Standard Contractual Clauses apply)
- Google acts as our "data processor" - see their DPA: Google Workspace Data Processing Amendment
Website Analytics:
- Processed via: Google Analytics 4 (only loads after you accept cookies)
- Data retention: 26 months (Google's default)
- IP anonymization: Enabled
Website Hosting:
- Infrastructure: Self-hosted on Raspberry Pi (Kolkata, India)
- SSL/TLS: Let's Encrypt certificate (256-bit encryption)
- Server logs: Minimal retention (30 days for troubleshooting)
International Data Transfers
Your data may be transferred to and processed in:
- India: Where our servers and business are located
- European Union: Via Google's EU data centers
- United States: Via Google's US data centers (protected by Standard Contractual Clauses)
For EU residents: We ensure adequate protection through Google's EU-approved Standard Contractual Clauses (SCCs). India's Digital Personal Data Protection (DPDP) Act 2023 governs how we handle data locally.
Security Measures
- ✅ HTTPS encryption for all website traffic
- ✅ Secure form submission via POST requests (no data in URLs)
- ✅ Honeypot anti-spam fields (hidden fields to detect bots - no personal data collected)
- ✅ Regular software updates and security patches
- ✅ Access-controlled Google Workspace (2-factor authentication enabled)
Limitation: As a bootstrapped startup operating on minimal infrastructure, we implement industry-standard security but cannot guarantee enterprise-grade protection. No electronic transmission is 100% secure. If you require higher security standards, please contact us before submitting personal information.
5. HOW LONG WE KEEP YOUR DATA
General Retention Period: 1 year from date of collection
| Data Type | Retention Period |
|---|---|
| Contact form inquiries | 1 year |
| UB Audit applications | 1 year |
| Web hosting inquiries | 1 year |
| Eyewear waitlist signups | Until launch (Q3-Q4 2026) + 1 year |
| Google Analytics data | 26 months (Google's default) |
| Server logs (IP addresses) | 30 days |
After retention periods expire, we will delete or anonymize your data. If we have ongoing legal obligations (e.g., tax records), we may retain data longer as required by Indian law.
6. YOUR PRIVACY RIGHTS
GDPR Rights (EU/EEA/UK Residents)
You have the right to:
- Access: Request a copy of your personal data we hold
- Rectification: Correct inaccurate or incomplete data
- Erasure ("Right to be Forgotten"): Delete your data (subject to legal obligations)
- Restriction: Limit how we process your data
- Portability: Receive your data in machine-readable format (CSV/JSON)
- Object: Opt-out of analytics or marketing communications
- Withdraw Consent: Revoke cookie consent or form submission consent at any time
India DPDP Act Rights (Indian Residents)
- Right to access and correction
- Right to erasure and data portability
- Right to nominate a representative
How to Exercise Your Rights
Email us at: contact@udvasbhattacharya.com
Subject line: "Privacy Rights Request - [Your Name]"
We will respond within:
- 30 days (GDPR standard)
- Free of charge for first request
- May require identity verification before processing
Right to Complain
If you're unhappy with how we handle your data, you can lodge a complaint with your local data protection authority:
- EU/EEA: European Data Protection Board - Contact List
- UK: Information Commissioner's Office (ICO)
- India: Data Protection Board of India (once operational under DPDP Act 2023)
7. COOKIES & TRACKING TECHNOLOGIES
We use cookies only for analytics purposes. Cookies are not loaded until you click "Accept" in our cookie consent banner.
What Cookies We Use
| Cookie Name | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics - Distinguish users | 2 years |
| _ga_* | Google Analytics - Session tracking | 2 years |
| ub_cookie_consent | Remember your cookie preference | 1 year |
How to Manage Cookies
- Via Cookie Banner: Click "Decline" to block all analytics cookies
- Via Browser Settings: Delete or block cookies in your browser preferences
- Chrome: Settings → Privacy → Cookies
- Firefox: Options → Privacy → Cookies
- Safari: Preferences → Privacy → Manage Website Data
- Google Analytics Opt-Out: Install Google Analytics Opt-out Browser Add-on
Note: Blocking cookies may affect website functionality (e.g., you'll see the cookie banner on every visit).
8. THIRD-PARTY SERVICES
Services We Use
- Google Workspace: Email, form processing, data storage
- Privacy Policy: Google Privacy Policy
- Data Processing Agreement: Google Workspace DPA
- Google Analytics: Website traffic analysis (with consent)
- How Google uses data: Google Partner Sites
- Instagram: Embedded social media content
- Privacy Policy: Instagram Privacy
- Let's Encrypt: SSL certificate provider (no data collection)
Payment Processors (External)
We do NOT process payments directly. When you purchase UB Audit or web hosting services, you'll be redirected to:
- PayPal or other payment gateways (their privacy policies apply)
- We never see or store your credit card details
- Payment processors may share transaction confirmation data (order ID, amount) with us
9. NEWSLETTER (Feature Not Yet Active)
Current Status: We do not currently offer newsletter subscriptions.
When We Launch:
- You'll explicitly opt-in via a separate signup form
- You can unsubscribe anytime via link in every email
- We'll update this Privacy Policy with specific newsletter terms
10. CHILDREN'S PRIVACY
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors.
If you are a parent/guardian and believe your child has provided us with personal information, please contact us immediately at contact@udvasbhattacharya.com and we will delete it within 48 hours.
11. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect:
- Changes in data protection laws
- New features or services
- Feedback from data protection authorities
How We Notify You:
- Update the "Last Updated" date at the top of this page
- For material changes: Email notification to users who've submitted forms in past 12 months
- Prominent notice on homepage for 30 days
Continued use of our website after changes constitutes acceptance of the updated policy.
12. CONTACT US
For any privacy-related questions, concerns, or requests:
Email: contact@udvasbhattacharya.com
Subject Line: "Privacy Inquiry - [Your Topic]"
Phone: +91 81000 90308 (WhatsApp available)
Response Time: Within 24-48 hours
Postal Address:
Udofera Consultancy Private Limited
B40/1, Kamdahari Narkel Bagan
Kolkata - 700084, West Bengal
India
Thank you for trusting us with your data. We take privacy seriously and continuously work to improve our practices. If you have suggestions or concerns, we genuinely want to hear from you.