Privacy Policy

Last updated: 23 August 2026

The short version.

  • We only collect what you type into a form, plus standard technical data your browser sends.
  • We use it to reply to you, quote your project, or assess your job application — nothing else.
  • We do not sell or rent your personal data, ever.
  • We do not send marketing newsletters. If we email you, it is because you contacted us.
  • You can ask us to show you, correct, or delete your data at any time by emailing inquiry@pingalit.com.

1. Who we are

Pingal IT Solutions ("we", "us", "our") builds custom software, websites and mobile apps. We operate https://pingalit.com and we are the data controller for the personal data described in this policy — meaning we decide what is collected and why.

Our development centre is at 148, Mangal Marg, Bapu Nagar, Jaipur, Rajasthan 302015, India. We work with clients in the United States, United Kingdom, Europe, Australia and elsewhere, so this policy is written to meet the standards of the strictest of those regimes rather than the loosest.

The data controller is PINGAL IT SOLUTIONS, registered in India, at the address above. If you need to identify us formally — for a data subject request, a regulator enquiry or your own vendor records — that is the entity to name, and inquiry@pingalit.com is the route to us.

2. What we collect, at a glance

Every piece of personal data this site collects, why we have it, and on what legal basis:

Personal data collected by Pingal IT Solutions, with purpose and legal basis
Where it comes from What we collect Why Legal basis
Enquiry & quote forms Name, email, phone (optional), your message, and a tag recording which page it came from To reply and to prepare a quote Steps taken at your request before a contract
Product enquiry forms Name, email, phone, message To answer questions about one of our products Steps taken at your request before a contract
Career applications Name, email, phone, your CV (PDF), optional cover letter To assess your application and contact you about it Steps taken at your request before a contract
Partner programme applications Name, email, phone, company website, services of interest, message, and the IP address used To assess your application; the IP address is a duplicate-and-fraud check on the referral scheme Your request, plus our legitimate interest in preventing referral fraud
Partner portal accounts Name, email, a hashed password To let approved partners sign in and manage their referrals Performance of the partner agreement
Referrals submitted by partners Details of a prospective client — see section 4 To follow up on a business referral Our legitimate interest in business development
Your browser, automatically IP address, browser and device type, pages visited, referring page Site security, spam prevention, and understanding site usage in aggregate Legitimate interests; consent for the analytics and advertising cookies

We never ask for payment card numbers, government identity documents, health information or any other special-category data anywhere on this site. Please do not send them to us by email either.

3. What we collect, in detail

Enquiry and quote forms

Used on the contact page, the homepage quote box, the service pages and our campaign landing pages. We collect your name, email address, phone number (optional on most forms), your message, and a short internal tag recording which page the enquiry came from so we know what you were reading. We use this only to reply to you and to discuss the work you asked about.

Career applications

If you apply for a role we collect your name, email address, phone number, your CV as a PDF and an optional cover letter. Your CV is stored as a file on our own server, not uploaded to a third-party recruitment platform. We check whether you have already applied for the same role, using your email address, so we do not process a duplicate application.

Partner programme applications and accounts

We collect your name, email address, phone number, company website, the services you are interested in, your message, and the IP address the application was submitted from. The IP address exists solely as a fraud and duplicate-submission check on the referral programme.

If your application is approved we create a partner portal account holding your name, email and a hashed password. We never store your password in a readable form and cannot recover it — only reset it.

Automatically collected data

Like any website, our server and our analytics tools receive technical information your browser sends: IP address, browser and device type, the pages you visit, and the page or search that referred you. Our forms also carry a hidden anti-spam field; it is checked and discarded on submission and is never stored against you.

4. If a partner gave us your details

This section applies to you if you never visited this website, but a referral partner of ours passed us your details as a prospective client. We are required to tell you this directly, so here it is in plain terms.

What we may hold: your name, your business name and website, your LinkedIn profile URL, your business and personal email addresses and phone numbers, the name and contact details of a point of contact at your organisation, your business address and location, and notes about the referral and any conversation that followed.

Where it came from: a referral partner in our partner programme, who is required to have a legitimate business reason for passing it on.

Why we have it: our legitimate interest in business development — following up on a business referral that may be relevant to you.

You can stop this at any time. Email inquiry@pingalit.com and ask us to delete your details or to stop contacting you, and we will. You do not need to give a reason, and we record the opt-out so you are not contacted again. You have every right listed in section 10, including the right to object.

When we first contact you, we tell you this directly. The first email we send always says where we got your details, why we are writing, and how to make us stop — it does not wait for you to come and find this page.

  • To answer you. When you send an enquiry, handling it is a step taken at your request before entering a contract.
  • Our legitimate interests. Running the site securely, preventing spam and referral fraud, keeping records of business enquiries, following up on referrals, and understanding in aggregate how the site is used. We have weighed these against your interests and use the minimum data that achieves them.
  • Your consent. Analytics and advertising cookies are set on the basis of your consent, which you can withdraw at any time (see section 8).
  • Performance of a contract. Running partner portal accounts and delivering work you have engaged us for.
  • Legal obligation. Where we must keep records — for example for tax or accounting — for as long as the law requires.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

6. Who else sees it

We do not sell, rent or trade your personal data. We never have. We share it only with the following, and only for the purposes described:

  • Google (Analytics, Tag Manager and Google Ads). These receive technical and usage data about your visit and set cookies in your browser. They do not receive the contents of the forms you submit. See Google's privacy policy.
  • Our email provider. Enquiries and applications reach us by email, so their contents pass through and are stored in our business mail system.
  • Bunny Fonts serves the site's web font. We chose it specifically because it does not set cookies or log personal data for tracking purposes.
  • Hostinger, our hosting provider, which stores this website, its database and the files uploaded through it — including CVs sent with job applications.
  • Professional advisers and authorities, where we are legally required to disclose, or need to establish or defend a legal claim.

WhatsApp. The WhatsApp buttons on this site are ordinary links. Clicking one takes you to WhatsApp, where your conversation with us is governed by WhatsApp's own privacy policy, not this one. We do not pass any data to WhatsApp from this website.

Social and review links. Our footer links to LinkedIn, Facebook, Instagram, Trustpilot and Dun & Bradstreet. These are plain links — those services only receive data about you if you click through to them.

7. International transfers

We are based in India. If you contact us from the UK, the EEA, Australia or the United States, your data will be transferred to and processed in India.

India is not the subject of a UK or EU adequacy decision. What that means for you depends on how your data reached us, so the three cases are set out separately rather than collapsed into a single claim.

If you sent us your details yourself

When you fill in a form on this site you are sending your data directly to us in India. You are the person it belongs to, not an intermediary passing it on, so this is not the kind of company-to-company transfer that needs a transfer contract behind it.

That does not put us outside the GDPR. Because we offer services to people in the UK and EEA, the UK GDPR and EU GDPR apply to us directly, and every right in section 10 is yours to exercise against us in exactly the same way. We answer those requests from India, within one month, free of charge.

If a partner passed us your details

Here there is an intermediary. If that partner is based in the UK or EEA then they are the one making the transfer, and their own safeguards govern it. We require referral partners to have a lawful basis for anything they pass to us, and you can object to us holding it at any time — see section 4, which also explains how we tell you where your details came from.

If you are a client and we process data for you

Where you engage us to build, host or maintain a system, you remain the controller of the personal data inside it and we act on your instructions. That relationship is governed by a written data processing agreement alongside your contract — covering the transfer safeguards and the hosting region — and not by this policy, which covers only what this website itself collects.

Our EU and UK representative

A company outside the UK and EEA that offers services into them normally has to appoint a local representative. There is a narrow exemption, and we have assessed our position against it rather than assuming it applies:

  • Our processing is occasional. We do not run continuous or systematic monitoring of anyone. We hold what people send us through a handful of business enquiry forms, and act on it when they ask us to.
  • We hold no special-category data at scale. This site never asks for health, biometric, racial, political, religious or criminal-offence data, and we ask you not to send it.
  • The risk to you is low. The data is business contact information and, if you apply for a role, your CV. We do not profile, score, sell or target anyone with it.

On that basis we do not currently appoint a representative. This is a judgement we have recorded, not an oversight, and we will revisit it if what we do changes. It changes nothing about your rights: you can exercise every one of them directly with us at inquiry@pingalit.com, and you can complain to your own national authority without going through us at all.

If we do appoint a representative, their name and address will be published in this section.

Data processing agreements for clients

If you are a client and need a written data processing agreement — with the Art. 28 terms and the appropriate transfer clauses for your region — ask us and we will put one in place before the work starts. It is a normal request, not an unusual one, and we would rather sign one than have you assume we would refuse.

If we build or host something for you

This section is about data you send us through this website. It is a separate question from where a system we build for you would run.

For client projects we deploy to Hostinger, Google Cloud Platform or Amazon Web Services, in the region you choose. If you need your data to stay in the UK, the EEA, Australia or anywhere else, we can host it there — the hosting region is a decision you make with us before the work starts, and it goes in your written agreement rather than being left to us to pick. Ask us if data residency matters to you; it is a normal request and the answer is usually yes.

8. Cookies and tracking

This site uses two kinds of cookies:

  • Strictly necessary. A session cookie and a security token that keep the site working and stop forged form submissions. These cannot be switched off and are never used to track you across sites.
  • Analytics and advertising. Set by Google Analytics, Google Tag Manager and Google Ads to measure how the site is used and how effective our advertising is. These can involve tracking across sites.

How we ask

Analytics and advertising cookies are not set until you agree to them. The scripts that set them are not loaded at all until you choose — not loaded-but-idle, not loaded-and-anonymised. If you have not chosen, or you chose to reject them, those scripts are absent from the page entirely.

  • Rejecting is as easy as accepting. Both are buttons on the same banner, side by side.
  • Your choice is remembered for 180 days, so you are not asked again on every page.
  • You can change your mind at any time using the Cookie settings link in the footer of every page. That clears your choice and shows the banner again.
  • Declining costs you nothing. Every part of this site works the same either way, and we do not ask again after you decline.

The only cookie we set before you choose is the one that records the choice itself, plus the session and security tokens that make forms work. None of them track you.

Other controls you have

Beyond the banner, you can clear or block cookies in your browser settings at any time, and most browsers let you block third-party cookies specifically. Blocking the analytics and advertising cookies does not affect your ability to use this site or to contact us. You can also opt out of Google Analytics using Google's browser add-on.

Do Not Track. There is no agreed industry standard for how sites should respond to a browser's Do Not Track signal, so this site does not currently respond to it. We would rather say so than imply a protection we do not provide.

9. How long we keep it

We keep personal data only as long as we have a reason to. Enquiries, applications, partner submissions and referrals are held so we can follow up and keep a record of the business relationship; accounting records are kept for the period tax law requires.

How long Pingal IT Solutions keeps each kind of record
What How long Why that long
Enquiries and quote requests 3 years after our last contact Long enough to pick up a project that was postponed, and to answer a question about work we quoted for.
Job applications and CVs 12 months after the application Long enough to consider you for a role that opens later, and to answer a question about the decision. Ask us and we will delete yours sooner.
Partner programme applications 2 years, unless you become a partner Approved partners are kept for as long as the partnership runs; declined and dormant applications are removed.
Referred leads that never became clients 2 years after the last activity A referral that has gone nowhere for two years is not a prospect any more. Opted-out records are deleted immediately.

The clock runs from your last contact with us, not from when we first heard from you — so an ongoing conversation is never deleted mid-thread. Anything we are legally required to keep (tax and accounting records, most obviously) is kept for as long as the law requires and no longer.

If you ask us to delete your data we will do so straight away, without waiting for the period above to run out — unless we are legally required to keep it, in which case we will tell you that, and why.

10. Your rights

These are the rights the UK GDPR and EU GDPR give you. We extend all of them to everyone who contacts us, wherever you live — we would rather run one honest process than a different standard per country.

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — ask us to delete your data where we have no overriding reason to keep it.
  • Restriction — ask us to pause using your data while a dispute is resolved.
  • Objection — object to processing we carry out on the basis of legitimate interests, including any outreach following a partner referral.
  • Portability — receive the data you gave us in a structured, machine-readable form.
  • Withdraw consent — at any time, without affecting anything done before you withdrew it.
  • Complain — to a supervisory authority (see section 15).

To exercise any of these, email inquiry@pingalit.com. We respond within one month. We may ask you to confirm your identity, but only enough to be sure we are not disclosing your data to someone else. Requests are always free, and we will never treat you differently, or refuse to work with you, because you made one.

11. Rights in your region

United Kingdom and European Economic Area

The rights in section 10 are yours under the UK GDPR and EU GDPR. You may complain to the UK Information Commissioner's Office or to your local supervisory authority in the EEA.

California

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information is collected and why, to request deletion or correction, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we do not knowingly sell the personal information of anyone under 16. The categories we collect are listed in section 2. Email inquiry@pingalit.com to exercise any of these rights; you will not be discriminated against for doing so.

Australia

If you are in Australia, we handle your personal information in line with the Australian Privacy Principles. You may complain to us first at inquiry@pingalit.com, and to the Office of the Australian Information Commissioner if you are not satisfied with our response.

India

As an Indian company we are subject to India's Digital Personal Data Protection Act, 2023. If you are in India you may ask us for a summary of the personal data we hold about you, ask for correction or erasure, and nominate someone to exercise your rights if you are unable to. Contact us at inquiry@pingalit.com.

12. Security and data breaches

Access to enquiries, applications, referrals and uploaded CVs is restricted to staff accounts in our admin system, each with explicitly granted permissions rather than blanket access. Passwords are stored hashed, never in readable form. The site is served over HTTPS.

No method of transmission or storage is completely secure, so we cannot promise absolute security. What we can promise is that we do not ask for payment card details, passwords or identity documents anywhere on this site — so there is nothing of that kind to lose.

If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you directly without undue delay where the risk to you is high.

13. Children

This site sells business services and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, email us and we will delete it promptly.

14. Changes to this policy

If we change this policy we will update the "last updated" date at the top. Material changes will be described here rather than made quietly, and where the change affects processing we already rely on your consent for, we will ask again.

15. Contact and complaints

For anything in this policy — including access, correction, deletion and objection requests — contact us:

PINGAL IT SOLUTIONS (registered in India)

148, Mangal Marg, Bapu Nagar, Jaipur, Rajasthan 302015, India

Email: inquiry@pingalit.com

Phone: +91 73571 88222

Hours: Mon–Fri, 09:00–19:00 IST (UTC+5:30)

If you are not happy with how we have handled your data, please tell us first — we would rather fix it. You can also complain to your national data protection authority, listed in section 11.


See also our Terms of Service.