PRIVACY NOTICE & DATA PROTECTION POLICY
Last Updated: October 1, 2026
Entity: Nurture IT Pvt Ltd.
This Privacy Notice is published by Nurture IT Pvt. Ltd. (hereinafter referred to as “Nurture IT”, “we”, “our”, or “us”) in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”).
This notice informs you, the Data Principal, regarding how we collect, store, handle, process, transfer, and protect your digital personal data when you use our website (nurtureit.in), engage our corporate IT services, or receive hardware and infrastructure support from us.
1. Scope & Business Operations
Nurture IT provides end-to-end enterprise IT infrastructure, hardware procurement, managed helpdesk services, and remote workforce logistics across India. In carrying out these day-to-day operations, we handle information in two straightforward ways:
- Direct Business & Client Purchases: When your organization engages us to purchase laptops, servers, or networking hardware, or submits an inquiry through our website, we process corporate contact and delivery details to provide quotes, fulfill purchase orders, issue GST tax invoices, and complete hardware shipments.
- Enterprise Support & Work-From-Home (WFH) Logistics: When your company partners with us to manage employee IT deployments, hardware upgrades, or home office deliveries, we receive designated recipient details (such as employee name, residential dispatch address, and contact number) solely to deliver, service, or retrieve company equipment on your employer’s authorization. All operational records are handled under strict confidentiality, stored securely on encrypted drives and role-restricted systems, and used exclusively to fulfill the requested logistics or support task.
2. Itemised Personal Data We Collect, Purposes, and Retention (Section 5)
Under Section 5 of the DPDP Act and Rule 3 of the DPDP Rules, 2025, we itemise below every category of personal data processed across our B2B operations, our service deliveries, and our digital platforms:
| Operational Context | Data Handled | Specific Operational Purpose | Storage & Security Safeguard | Retention Period |
| B2B Hardware Purchases & Enterprise Orders | Company contact person’s name, corporate email, phone, billing address, company delivery address, GSTIN | Fulfilling purchase orders, scheduling hardware dispatches, issuing statutory tax invoices, and tracking warranty support. | Processed on-premises at our corporate office via Tally ERP, with an encrypted secondary backup maintained on Microsoft OneDrive for business continuity (Rule 6(1)(d)); access is restricted via multi-factor authentication and role-based permissions. | 8 years (statutory requirement under Indian GST and Companies Act). |
| WFH Logistics & Doorstep Hardware Delivery | Recipient employee name, residential shipping address, phone number, corporate email | Packaging, dispatching, and tracking doorstep deliveries or returns of company-assigned laptops/kits via trusted courier partners (Delhivery, Blue Dart). | Stored encrypted secure systems with access limited strictly to dispatch personnel. | Kept only for the duration of the shipment and retained for 1 year to resolve transit status and warranty claims. |
| Website & Service Inquiries | Name, corporate email, contact number, company name, message details | Responding to technical queries, quotation requests, and infrastructure consultations. | Stored securely on our proprietary CRM hosted on a Virtual Private Server (VPS) located in Mumbai, India; never sold or rented to third-party brokers. | 2 years from the date of last active communication or inquiry resolution. |
| Marketing & Communications | Name, business email, communication preferences | Sending service updates, technology advisories, and commercial proposals via cloud marketing infrastructure (HubSpot). | Hosted on secure cloud infrastructure located in the United States (West) with strict access credentials & 2FA. | Retained until you withdraw consent or click “Unsubscribe” in promotional emails. |
| Job Applicant Data | Name, contact details, curriculum vitae (CV), employment history (received via job portals like Naukri) | Evaluating qualifications, conducting interviews, and recruitment screening. | Stored locally on encrypted company-managed storage accessible only by designated recruitment leads. | 1 year from the date of application for unsuccessful candidates, unless active consent is given for future openings. |
| Technical & Security Data | IP address, browser type, device identifiers, server access logs | Ensuring server security, preventing automated bot abuse, mitigating cyber threats, and complying with statutory log retention mandates. | Stored in protected server access logs restricted to system administration personnel. | Minimum 1 year in accordance with Rule 6(1)(e) and Rule 8(3) of the DPDP Rules, 2025. |
3. Trackers, Cookies, and GTM Consent
- Default-Denied Analytics: In accordance with Section 6 of the DPDP Act, all non-essential scripts, trackers, and analytics tools (including Google Tag Manager and Google Analytics) are set to a default-denied state and will not drop tracking cookies until you provide affirmative consent via our banner.
- Consent Withdrawal: In accordance with Section 6(4), withdrawing your consent is as simple as giving it. You can review or adjust your tracker preferences at any time by clicking the “Cookie Preferences” link in our website footer.
4. Third-Party Processors & Cross-Border Transfers (Section 16)
To deliver enterprise IT solutions, we partner with specialized service providers who process data strictly under confidentiality and data protection obligations:
- Logistics Partners: We share employee delivery details with express courier partners (including Delhivery, Blue Dart, and verified logistics vendors) solely to execute doorstep deliveries across India.
- Hosting, Backup & Marketing Infrastructure: Our primary business CRM operates on a secure Virtual Private Server (VPS) located in Mumbai, India, ensuring domestic data localization for client inquiry records. Invoicing, statutory accounts, and billing records (Tally) are maintained on-premises at our Indiranagar headquarters, with encrypted disaster recovery backups synchronized to Microsoft OneDrive cloud infrastructure under enterprise security controls pursuant to Rule 6(1)(d).
- Promotional email communications and marketing automation are managed through HubSpot Inc., which processes data on cloud servers located in the United States (West).
- All cross-border data transfers comply with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, 2025, and are conducted using secure, encrypted protocols without transferring data to restricted overseas territories.
5. Policy on Children’s Personal Data (Section 9)
Nurture IT is a business-to-business (B2B) enterprise IT technology provider.
- Our website, platforms, and corporate IT services are strictly intended for adults (individuals who have completed 18 years of age).
- We do not knowingly collect, solicit, or process personal data from children under 18.
- We do not track the browsing habits or engage in behavioral monitoring of minors. If we become aware that personal data of a minor has been submitted without verifiable parental consent, we will promptly delete it from our systems.
6. Your Statutory Data Principal Rights (Section 11–14)
Under Chapter 3 of the DPDP Act, 2023, you have the following legal rights regarding your personal data:
- Right to Access (Section 11): Request a summary of your personal data being processed and the processing activities undertaken.
- Right to Correction & Updating (Section 12): Request the correction, completion, or updating of inaccurate or misleading personal data.
- Right to Erasure (Section 12): Request the deletion of your personal data when the original business purpose has been fulfilled, unless retention is legally required by applicable Indian statutes.
- Right to Withdraw Consent (Section 6(4)): Withdraw consent previously granted for optional communications or marketing at any time.
- Right to Nominate (Section 14): Designate an authorized representative to exercise your data rights in the event of death or incapacity.
- Right of Grievance Redressal (Section 13): Access a fast, structured mechanism to resolve data privacy complaints.
(Note: If your personal data was provided to us by your employer under an enterprise AMC or WFH contract where Nurture IT acts as a Data Processor, you may also exercise these rights directly through your employer’s HR or IT administration).
How to Exercise Your Rights (Rule 14 Intake):
You can exercise any of these statutory rights by emailing our centralized Data Protection Grievance Desk at grievance@nurtureit.in with the subject line “Data Principal Rights Request”. Please specify your registered corporate email or phone number to verify your identity pursuant to Rule 14(5).
7. Grievance Redressal Officer (Section 8(10) & Rule 9)
In accordance with Section 8(10) of the DPDP Act and Rule 9 & Rule 14(3) of the DPDP Rules, 2025, our designated Grievance Officer details are published below:
- Name: Indrajit C
- Designation: Grievance Officer
- Entity: Nurture IT Pvt. Ltd.
- Grievance Email: grievance@nurtureit.in
- Principal Corporate Office:50, 9th A Main Rd, 1st Stage, Indiranagar, Bengaluru, Karnataka 560038
- Branch Office:59, Sampige, East Park Road, 15th Cross Rd, Malleshwaram, Bengaluru, Karnataka 560003
- Operating Hours: Monday to Friday, 10:00 AM – 6:00 PM IST
- Response Timelines (SLA): Acknowledgment within 48 hours; complete resolution within 30 days.
- Regulatory Escalation: If you are dissatisfied with our resolution, you have the statutory right to lodge an appeal with the Data Protection Board of India (DPBI) pursuant to Section 18 of the DPDP Act and Rule 19.
