Privacy Policy
Last updated: March 16, 2025
YakshLabs ("we," "our," or "us") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit yakshlabs.com or engage our services.
1. Overview
This policy applies to all personal data processed in connection with YakshLabs's website, products, and professional services. We operate from India and serve clients globally, including the European Union (EU) and the United Kingdom (UK). We comply with:
- The General Data Protection Regulation (GDPR) — EU/UK
- India's Digital Personal Data Protection Act 2023 (DPDP Act)
- Other applicable data protection laws in the territories we operate
2. Information We Collect
We collect the following categories of personal information:
Identity & Contact Data
Name, email address, phone number, company name, job title — provided when you fill out contact forms or request a consultation.
Usage & Technical Data
IP address, browser type, operating system, pages visited, time spent on pages, referral URLs — collected automatically via cookies and analytics tools.
Project & Communication Data
Project briefs, requirements documents, and messages exchanged during onboarding and delivery.
We do not collect sensitive personal data (e.g., biometric data, health information, financial account credentials) unless explicitly required for a specific project and separately consented to.
3. How We Use Your Information
We process your personal data for the following lawful purposes:
- Service Delivery: Responding to enquiries, scoping projects, and delivering contracted services.
- Contract Performance: Managing client agreements, invoices, and project milestones.
- Legitimate Interests: Improving our website, analysing usage patterns, and enhancing user experience.
- Legal Compliance: Fulfilling obligations under applicable Indian and international laws.
- Marketing (with consent): Sending newsletters or case studies — only where you have explicitly opted in.
We never sell your personal data to third parties. Ever.
6. Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting obligations. Typically:
- Client project data: 7 years (statutory accounting requirement under Indian law)
- Contact/enquiry data: 2 years from last interaction
- Website analytics: 26 months (Google Analytics default, anonymised)
- Marketing consent records: Until consent is withdrawn or 3 years, whichever is earlier
7. Your Rights (GDPR & DPDP)
Depending on your jurisdiction, you have the following rights regarding your personal data:
Right of Access
Obtain a copy of your personal data we hold.
Right to Rectification
Correct inaccurate or incomplete data.
Right to Erasure
Request deletion of your data ("right to be forgotten").
Right to Restrict Processing
Limit how we process your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent
Withdraw consent at any time where processing is consent-based.
Right to Grievance (DPDP)
Lodge a complaint with India's Data Protection Board.
To exercise any of these rights, email us at hello@yakshlabs.com. We will respond within 30 days of a verified request.
8. Data Security
We implement industry-standard technical and organisational measures to protect your data, including TLS encryption in transit, AES-256 encryption at rest, access controls with least-privilege principles, regular security audits, and SOC 2-aligned development practices. While no method of transmission over the internet is 100% secure, we continuously improve our security posture to protect your information.
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently received data from a person under 18, we will take steps to delete that information promptly.
10. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by sending you an email notification. We encourage you to review this policy periodically.
11. Contact Us
For privacy-related enquiries, data subject requests, or questions about this policy, please contact our Data Privacy point of contact: