01The short version
- We don’t use analytics, advertising or tracking cookies on this website.
- We only collect what you choose to send us through the contact form, plus the minimum technical data needed to run and protect the site.
- We use it to reply to you — never to sell, rent or trade it.
- Client confidentiality is how we work: we never publish who our clients are without their permission.
02Who we are
This website, insigconsulting.com, is operated by Insig Consulting (“Insig”, “we”, “us”), a technology consultancy based at 1st Floor, Shefalika Apartment, Garia, Kolkata, West Bengal, India (GSTIN 19ATPPB5147F1ZL).
For the personal data described in this policy, Insig is the data fiduciary (under India’s Digital Personal Data Protection Act, 2023) and the data controller (under the EU/UK GDPR, where it applies).
03What we collect
Information you give us
When you use the contact form or email us, we receive:
- Your name and email address (required).
- Company and website (optional).
- The topics you select and your message — please don’t include sensitive personal data (such as health or financial details) in a first message.
Information collected automatically
- IP address — included in the enquiry notification we receive, and used in hashed (non-reversible) form to limit repeated submissions from the same network.
- Security-check signals — the contact form uses Cloudflare Turnstile to tell people from bots. Turnstile processes limited browser and device signals for that purpose only.
- Server logs — like every website, our hosting provider’s web server automatically records technical request data (IP address, date and time, page requested, browser type, referring page) for security and troubleshooting.
We do not use analytics tools, advertising pixels, social-media trackers or session-recording software.
04How we use it
- To read and reply to your enquiry, and to discuss a potential engagement with you.
- To protect the website and contact form from spam, abuse and attacks.
- To keep records of business correspondence, and to meet legal, tax and accounting obligations.
We will not add you to a mailing list or send you marketing unless you ask us to. We do not make automated decisions about you, and we do not use your data to train AI models.
05Legal basis
- Consent — you choose to send us your details through the form or by email. You can withdraw consent at any time (see Your rights); this does not affect anything done before you withdrew it.
- Legitimate uses / legitimate interests — keeping the website secure and preventing spam and abuse.
- Steps before a contract — responding to your request about our services.
- Legal obligation — keeping records required by law.
06Who we share it with
We don’t sell or rent personal data. We only share it with service providers who help us run this website, under appropriate confidentiality and data-protection terms:
| Provider | Purpose | Data involved |
|---|---|---|
| Our web hosting provider | Hosting the website, server logs, and the email server that delivers enquiry notifications | Form contents, IP address, technical request data |
| Cloudflare, Inc. | Turnstile bot protection on the contact form | Browser/device signals, IP address |
| Our email provider | Receiving and storing the enquiry in our inbox | Form contents, IP address |
We may also disclose information where required by law, to enforce our rights, or to protect the safety of any person.
07Cookies & tracking
This website does not set any cookies of its own and does not use analytics or advertising trackers.
On the contact page, Cloudflare Turnstile may use strictly necessary technologies (such as short-lived browser storage) to complete the security check. These are not used for advertising or to track you across websites. See Cloudflare’s Turnstile privacy notice for details.
08How long we keep it
- Enquiries that don’t lead to a project — kept for up to 24 months, then deleted.
- Enquiries that lead to a project — kept for as long as our business relationship lasts, plus any period required by law (for example, tax and accounting records).
- Rate-limit records — hashed, not linked to your identity, and disregarded after one hour.
- Server logs — kept by our hosting provider for a limited period according to their standard practice.
You can ask us to delete your enquiry sooner at any time.
09Security
The site is served only over encrypted HTTPS connections. Enquiries are sent using authenticated, encrypted email transport. Access to enquiries is limited to people at Insig who need it. Our email address is published in a form that automated harvesters can’t easily read. No method of transmission or storage is completely secure, but we take reasonable steps to protect your data and will notify you and the authorities of any personal data breach where the law requires it.
10International transfers
We are based in India, and many of our clients are in the United States. Our service providers (for example, Cloudflare) may process data in other countries. Where data is transferred across borders, we rely on providers with appropriate safeguards and comply with any restrictions notified under applicable law.
11Your rights
Depending on where you live, you can ask us to:
- Tell you what personal data we hold about you and how we use it.
- Correct, complete or update it.
- Delete it, or stop using it (including by withdrawing your consent).
- Object to or restrict certain uses, or receive a copy of it in a portable format (where GDPR applies).
- Nominate another person to exercise your rights if you die or become incapacitated (under India’s DPDP Act).
To make a request, contact us using the details below. We’ll respond within 30 days (or sooner where the law requires) and may need to verify your identity first. You also have the right to complain to a data protection authority — in India, the Data Protection Board of India; in the EU/UK, your local supervisory authority — although we’d appreciate the chance to resolve your concern first.
12Client & project data
This policy covers our website. When we build or run systems for clients, any personal data inside those systems is handled under our agreements with each client, where we usually act as a data processor on the client’s instructions. The case studies on this site are anonymised. The people, names and figures shown in the product illustrations are fictional.
13Children
This website is intended for business users and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, please contact us and we will delete it.
14Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows when it last changed. Significant changes will be highlighted on this page.
15Contact & grievances
For privacy questions, requests or complaints, contact our Grievance Officer through the Privacy & Grievance Desk:
- Grievance Officer: Privacy & Grievance Desk, Insig Consulting
- Email: Show email address
- Post: 1st Floor, Shefalika Apartment, Garia, Kolkata, West Bengal, India
- Contact form: insigconsulting.com/contact-us
We aim to acknowledge grievances within 72 hours and resolve them within 30 days.