This policy explains what personal data we hold, why we hold it, how long we keep it, and what you can ask us to do about it. It covers this website and the enquiries that reach us through it. We collect as little as the work allows, we hold it no longer than we need to, and we delete it on request.
1. Who is responsible
Dunime is the Data Fiduciary for personal data collected through this website. "Data Fiduciary" is the term India's Digital Personal Data Protection Act 2023 uses for what other laws call a data controller: the party that decides why and how personal data is processed.
Dunime Technologies Private Limited, CIN U62020DC2026PTC473332, operating from Delhi NCR, India, decides why and how personal data reaching this website is handled, and is the data fiduciary for it under the Digital Personal Data Protection Act 2023.
Every privacy question, request and complaint goes to director@dunime.com. That address reaches the person able to answer it. It is the only address Dunime uses; there is no other.
2. The two roles we act in
The difference matters, because it decides who you should ask about your data.
- When you browse this site or send us an enquiry, we decide what happens to your data. We are the Data Fiduciary under Indian law and the controller under the GDPR. This policy governs that.
- When we build, run or test a system for a client, the client decides what happens to the personal data inside it and we act on their documented instructions. We are a Data Processor under Indian law and a processor under the GDPR. What we may do with that data is set by the engagement contract and its data processing terms, not by this page. If your data sits in a client's system, the client is the right party to ask, and we will help them answer you.
3. What we collect
Things you send us deliberately:
- From the enquiry form on the contact page: the service you select, your name, your organisation, your work email, your phone number if you give one, your message, and whether you tick the box saying the enquiry involves a live security issue or needs an NDA first.
- From email: whatever you choose to put in it, including anything attached.
Things created automatically when you visit:
- Standard web server logs held by our hosting provider: your IP address, the date and time, the pages and files requested, the page that referred you, and your browser's user agent string.
Enquiries submitted through the form are posted to a handler on this same server, which delivers them to our mail server. Nothing is passed to a third-party form service, and no copy is kept on the web server beyond delivery.
4. What your browser contacts when you load this site
A page reveals your IP address to any server it asks for a file. We would rather list those servers than let you discover them in the network tab.
- Google Fonts (fonts.googleapis.com and fonts.gstatic.com), on every page, to load the typefaces the site is set in. Your IP address and browser details reach Google.
- unpkg.com and cdn.jsdelivr.net, on the contact page only, for the script and map data behind the globe illustration. The same exposure, two more parties.
- Our hosting provider, which serves every request and therefore sees every request. It also inserts a script of its own (tccl.min.js, served from img1.wsimg.com) into pages on their way out. That script is not part of our source code, we did not add it, and we receive nothing from it.
We do not control what those providers log or how long they keep it. We intend to serve the fonts and the map data from our own server, so that loading this site contacts nobody but us.
5. What we do not do
- We do not sell, rent or trade personal data.
- We do not run advertising, retargeting or cross-site tracking pixels.
- We do not profile you and we make no automated decisions about you.
- Our own code sets no cookies. The home page stores a single value in your browser's session storage so the opening animation does not replay; it never leaves your device and it disappears when you close the tab. What our hosting provider's injected script does is covered in section 4.
- We run no analytics on this site today.
6. Why we hold it
- To answer your enquiry and take the steps you asked us to take towards a contract.
- To perform a contract once one exists, and to invoice under it.
- To keep the records a business is required by law to keep, including tax and company records.
- To keep the site and our own systems secure and to investigate abuse. Server logs exist for this.
Under the DPDP Act, processing personal data needs either your consent or one of the "certain legitimate uses" the Act lists, such as data you voluntarily provide for a purpose you have not objected to. Where we rely on consent, you can withdraw it at any time, and withdrawing it has to be as easy as giving it was. Withdrawal stops future processing; it does not undo what was lawfully done before.
7. How long we keep it
- Enquiries that do not become engagements: held on our mail server for up to 24 months, so a conversation can be picked up where it was left. Deleted sooner on request.
- Engagement and billing records: retained for eight financial years, which is the period the Companies Act 2013 and Indian tax law require books and supporting records to be preserved.
- Security testing evidence, findings and reports: held under the terms of the engagement that produced them, and returned or destroyed as that engagement requires.
- Web server logs: generated and retained by our hosting provider under its own defaults, and not separately copied or analysed by us. Where the CERT-In directions of April 2022 apply, the 180-day floor below governs.
Two legal floors sit underneath those periods and can extend them. CERT-In's directions of April 2022 require logs of information and communication technology systems to be maintained for 180 days and held within India. From 13 May 2027, Rule 6 of the DPDP Rules 2025 requires logs giving visibility over access to personal data, and the personal data itself where that is needed for the purpose, to be kept for at least one year unless another law says otherwise.
9. Data crossing borders
We are based in India and work with clients in India, Hong Kong, Singapore and Germany, so data does cross borders.
Out of India. Rule 15 of the DPDP Rules 2025 takes a negative-list approach: personal data may be transferred outside India unless the Central Government restricts a particular country or territory by order. No such order has been made as at the date on this page. If one is made that affects us, this section will say so.
Into India from Europe. India does not hold an adequacy decision from the European Commission. Transfers of personal data from the EU or EEA to us therefore rest on the Commission's Standard Contractual Clauses, supported by a transfer impact assessment, alongside a data processing agreement meeting Article 28 of the GDPR.
Into India from Hong Kong and Singapore. Clients there carry their own obligations when they send personal data to a service provider abroad, including a duty to bind us contractually to a comparable standard of protection. Those obligations are handled in each engagement contract.
10. Security
Access to systems holding personal data is limited to the people who need it, granted individually, and revoked when the need ends. Credentials are not shared between people. Traffic to and from this site is encrypted in transit. Given what we sell, we hold ourselves to the controls we would expect to find in a client.
Rule 6 of the DPDP Rules 2025 sets the baseline a Data Fiduciary must meet from 13 May 2027: encryption, obfuscation, masking or tokenisation as appropriate; controls on who can access what; logging and monitoring of access to personal data; backups sufficient to recover from loss; and equivalent obligations written into contracts with any processor.
Nobody can promise a system will never be breached, and we will not pretend otherwise. What we can tell you is what we do, and what we would do if it happened, which is the next section.
11. If there is a personal data breach
Section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025 require a Data Fiduciary to tell the Data Protection Board of India and every affected person without delay, then give the Board a fuller report within 72 hours covering the facts, the cause, what was done to contain it, and what will stop it recurring. CERT-In's directions run in parallel on a six-hour clock for the incident types they list.
What you would get from us: what happened, which of your data was involved, what we have done about it, and what we suggest you do. In plain words, not a press release.
12. Your rights
Under the DPDP Act you can ask us to:
- give you a summary of the personal data we hold about you, what we do with it, and who we have shared it with;
- correct it, complete it, or bring it up to date;
- erase it, unless we are required to keep it for a legal purpose;
- act on your withdrawal of consent;
- recognise a person you nominate to exercise these rights for you if you die or become unable to exercise them yourself.
Write to director@dunime.com. We may need to establish that you are who you say you are before acting, particularly on erasure. The DPDP Rules set an outer limit of 90 days for resolving a grievance.
If you are in the EU, the EEA or the UK, the GDPR gives you a comparable set of rights and adds the rights to object, to restrict processing, and to receive your data in a portable form. Where we hold your data on a client's behalf rather than our own, we will pass your request to that client, because the decision is theirs.
13. Children
This is a business-to-business site. It is not directed at children and we do not knowingly collect their data. The DPDP Act treats anyone under 18 as a child, requires verifiable consent from a parent or lawful guardian before their data is processed, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. If you believe a child has sent us personal data, tell us at director@dunime.com and we will delete it.
14. Complaints
Tell us first, plainly, at director@dunime.com. If we do not put it right, you can take it to the Data Protection Board of India, constituted on 13 November 2025 under the DPDP Rules 2025. If you are in the EU, the EEA or the UK, you may complain to your own national supervisory authority instead.
If you have found a security flaw in this website rather than a privacy problem, section 3 of the Terms of Service sets out how to report it and what we undertake in return.
15. Changes to this policy
This page will change as facts are settled and as the DPDP Rules phase in across 2026 and 2027. The date at the top is the date of the version you are reading. Material changes will be described here rather than made quietly.
16. The law referred to on this page
- Digital Personal Data Protection Act, 2023 (India).
- Digital Personal Data Protection Rules, 2025, notified 13 November 2025 as G.S.R. 846(E). Rules 1, 2 and 17 to 21 took effect on notification; Rule 4, on Consent Managers, takes effect 13 November 2026; Rules 3, 5 to 16, 22 and 23, which carry most of the duties described above, take effect 13 May 2027.
- Information Technology Act, 2000, including section 43A and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which remain in force through the transition to the DPDP regime.
- CERT-In Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000.
- Regulation (EU) 2016/679, the General Data Protection Regulation, where it applies to work for clients in the European Union.
This page is written from the primary sources and states the position as at the date above. Where the law changes, this page changes with it.