Privacy & Data Protection Policy
Effective Date: September 23, 2026. Aligned with India Digital Personal Data Protection Act 2023 (DPDP Act), EU General Data Protection Regulation (GDPR), and US CAN-SPAM Act.
1. Data Fiduciary Identity & Scope
KiteTap acts as a Data Fiduciary for personal data submitted via our consultation intake forms and a Data Processor for technical mailbox provisioning performed on behalf of our enterprise clients. Contact: privacy@kitetap.com.
2. Lawful Grounds for Processing
- India DPDP Act 2023 (Section 4): Explicit consent obtained through affirmative checkbox confirmation prior to brief submission.
- EU GDPR Article 6(1)(b): Processing necessary for the performance of an infrastructure implementation contract or pre-contractual steps.
- EU GDPR Article 6(1)(f): Legitimate interest in securing network endpoints, preventing DoS attacks, and validating DNS records.
- US CAN-SPAM Act: All commercial correspondence from KiteTap includes physical business addresses, single-click opt-out mechanisms, and genuine sender identification.
3. Data Minimization & Retention Schedule
We collect solely: Name, business work email, company domain, and fleet architectural requirements. Project inquiry records are purged after 90 days following project completion. We do not sell, rent, or syndicate client information to advertising networks, lead aggregators, or third-party marketing brokers.
4. Grievance Redressal Officer (DPDP Act 2023)
5. Data Principal Rights
Residents of India and the European Economic Area possess the statutory right to: (a) access summaries of personal data held; (b) demand immediate correction or erasure of outdated information; (c) withdraw consent at any time; and (d) lodge complaints directly with the Data Protection Board of India or relevant EU Data Protection Authorities.