Legal & compliance · Active policy

Privacy Policy

Effective date: October 1, 2025Last updated: October 2025GDPR · CCPA/CPRA rights

Startwyse (“Startwyse,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, store, and protect information when you visit our website, interact with our services, contact us, request a consultation, submit an enquiry, apply for a role, or otherwise interact with Startwyse.

We do not sell data
Mutual NDA on request
Encrypted in transit
GDPR & CCPA rights
01

About Startwyse

Startwyse is a product engineering and technology consulting company providing software engineering, cloud architecture, system modernization, and technical advisory services to startups and growing businesses.

This Privacy Policy applies to personal information gathered through our public website (startwyse.com), discovery and consultation forms, marketing channels, and client onboarding communications.

02

Information we collect

We collect information to provide engineering services, deliver proposals, assess applications you send us, and understand how the website is used.

2.1Information you provide to us

You may voluntarily submit personal data when engaging with us:

  • Contact data: Name, business email, phone number, and company location.
  • Project scope & enquiries: Technical context, objectives, budgets, and timelines submitted via discovery forms.
  • Career data: Résumés, portfolios, employment history, and references if you apply or send a CV.
  • Correspondence: Feedback, support requests, or general enquiries via email or scheduled calls.

Notice on sensitive data: Please do not submit production credentials, private encryption keys, raw end-user personal data, or proprietary codebases through our public website forms. Secure transfer channels are arranged during formal onboarding.

2.2Information collected automatically

When you browse our website, we and our analytics provider may log:

  • Device & technical data: IP address, browser type and version, language, operating system.
  • Usage information: Pages visited, referral URLs, time on page, and similar interaction data.
  • Approximate location: Country or city derived from IP address.
03

How we use information

We process personal information for legitimate commercial and engineering purposes:

Consulting & architecture scoping

To review technical requirements, evaluate roadmaps, prepare proposals, and execute statements of work.

Communication & project support

To reply to enquiries, schedule discovery calls, and send updates on active engagements.

Hiring & applications

If you send a CV or apply for a role, to review qualifications and coordinate interviews.

Security & legal compliance

To detect abuse, protect our infrastructure, enforce our terms, and meet statutory obligations.

04

Legal basis for processing (EEA / UK / GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following lawful bases under the GDPR to collect and process personal data:

  • 1. Performance of a contract: Processing required to perform contractual duties or take pre-contractual steps you request (for example scoping, NDAs, or statements of work).
  • 2. Legitimate interests: Processing necessary to run and secure the website, respond to business enquiries, and improve our services, provided your rights do not override those interests.
  • 3. Consent: When you opt in to non-transactional marketing, or when optional analytics cookies require consent in your region.
  • 4. Legal compliance: When retention or disclosure is required by law, tax rules, or a competent authority.
05

Cookies and similar technologies

We use first-party cookies, similar storage, and Google Analytics cookies to operate and understand the website.

CategoryPurposeDuration
Essential / necessarySite operation, routing, and security on the pages you request.Session / persistent
AnalyticsGoogle Analytics measures aggregated traffic, page views, and referral sources so we can improve the site.Up to 13 months

You can control or disable non-essential cookies in your browser. Blocking essential cookies may affect site behaviour. You can also use Google’s analytics opt-out tools where available.

06

Third-party services & processors

We use established vendors to host the site, measure usage, store enquiry forms, and communicate with you. These providers process data under their own terms and, where applicable, data-processing agreements:

  • Website hosting & CDN: Cloud hosting and edge delivery for startwyse.com and related static assets.
  • Analytics: Google Analytics (measurement ID G-QJ2R3TNGYX) for anonymized usage statistics.
  • Enquiry storage: Supabase stores consultation and enquiry submissions you send through our contact form.
  • Email & operations: Business email and related tools used to reply to you and manage active client work.
07

Sharing of information

We do not sell, rent, or broker your personal information to third parties.

We only share personal data in the following situations:

  • Service providers: Vendors who process data under our direction for hosting, analytics, email, and form storage.
  • Legal & regulatory obligations: When compelled by law, court order, or to prevent fraud or abuse.
  • Corporate reorganization: In connection with a merger, sale of assets, or similar transaction, with notice where required.
  • With your consent: When you authorize us to share information with a designated partner or client.
08

Data retention

Startwyse retains personal data only as long as needed for the purposes in this policy, unless a longer period is required by law, accounting, or a client contract.

  • Enquiry & consultation leads: up to 24 months from last active contact, unless you request deletion sooner.
  • Client account records: for the engagement plus the period required for audit, tax, and contract obligations.
  • Job applications: typically up to 12 months unless you ask us to remove them earlier.

When a retention window ends, we delete or de-identify records using the tools available in our systems.

09

Data security

We apply practical technical and organisational measures to protect information from loss, misuse, unauthorised access, disclosure, alteration, and destruction:

TLS in transit
Encrypted connections

The public website is served over HTTPS. Form and email traffic uses encrypted transport where the provider supports it.

Access control
Need-to-know access

Client and enquiry records are limited to people working the engagement. We do not publish intake data.

Vendor controls
Hosted infrastructure

Hosting, analytics, and form storage run on established cloud vendors that publish their own security practices.

No internet transmission or hosted system is completely secure. You accept this residual risk when using any online service.

10

International data transfers

Startwyse operates from India and uses cloud infrastructure that may be hosted in the United States, the European Union, India, or other regions.

If your data is transferred outside your home country (including outside the EEA or the United Kingdom), we rely on appropriate transfer mechanisms where required, which may include:

  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Addendum (IDTA)
  • Adequacy decisions issued by a competent authority
11

Your privacy rights

Depending on your jurisdiction (for example GDPR or CCPA / CPRA), you may have the following rights:

Right to access / knowRequest confirmation whether we process your data and obtain a copy of records we hold.
Right to rectificationAsk us to correct inaccurate, incomplete, or out-of-date personal data.
Right to erasureRequest deletion of your information, subject to statutory retention obligations.
Right to restriction & objectionObject to processing based on legitimate interests, or ask us to pause processing.
Right to data portabilityReceive personal data you provided in a structured, commonly used machine-readable format.
Right to non-discriminationWe will not deny services or change engineering quality because you exercise privacy rights.

To exercise these rights, email business@startwyse.com. We will confirm receipt and respond within a reasonable period, typically within 30 days.

12

Marketing communications

If you subscribe to newsletters or product notes, you may unsubscribe at any time using the link in the email or by writing to us.

After opting out of promotional mail, you may still receive transactional messages about an active engagement, invoices, or important security notices.

13

Children’s privacy

Our website and consulting services are intended for businesses and adult professionals. We do not knowingly collect personal data from anyone under 16.

If we learn that we collected information from a child under 16, we will delete that record.

14

Third-party links & integrations

Our site may link to third-party services, repositories, documentation, or client examples. We do not control the privacy practices of those sites.

Review the privacy notices of any third-party websites you visit.

15

Changes to this Privacy Policy

We may update this policy to reflect product, legal, or operational changes. When we do, we will revise the “Last updated” date at the top of this page.

For material changes, we will post a notice on the site or email active clients before the changes take effect where required.

16

Contact the privacy team

Questions about this policy or our data practices can be sent through the channels below. For a discovery call, use the contact page.

Legal name
Startwyse
Product engineering & technology consulting
Privacy contact
business@startwyse.com
Office

Regus — The Estate, 8th FloorDickenson RoadBengaluru 560042India

17

Applicable law and dispute resolution

This Privacy Policy is governed by the laws of India, without regard to conflict-of-law principles. Courts in Bengaluru, Karnataka shall have jurisdiction, except where applicable consumer or data-protection law requires otherwise.

If you are in the EEA or the United Kingdom, your right to lodge a complaint with your local Data Protection Authority or the UK Information Commissioner’s Office is unaffected.