Privacy policy
Last updated: September 2026 · Havik ProtoLabs Pvt. Ltd.
Draft for review. This text is a starting point written for Havik ProtoLabs. Have it reviewed by a lawyer familiar with the Indian DPDP Act 2023, the IT Act 2000 and, if you serve EU customers, the GDPR, before publishing.
1. Who we are
Havik ProtoLabs Pvt. Ltd. ("Havik", "we", "us") is a software development company registered in India, with its office at 3rd Floor, Nile Complex, Kanta Toli, Ranchi – 834001, Jharkhand, India. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for the personal data described in this policy; for the purposes of the EU General Data Protection Regulation ("GDPR"), where it applies, we are the controller.
Contact for privacy matters: info@havik.in. Grievance Officer (DPDP Act, s. 8(10)): [NAME], [EMAIL], [PHONE]. We acknowledge grievances within 48 hours and respond within 30 days.
2. What this policy covers
This policy applies to havik.in, to enquiries and correspondence with us, and to our provision of software development services. Our products — echoSignals, Privyie and others — have their own privacy notices where they process personal data; those notices govern the products.
3. Data we collect and why
| Data | Source | Purpose | Legal basis (GDPR) / consent (DPDP) |
|---|---|---|---|
| Name, company, work email, phone, message content | Contact form, email, calls | Responding to your enquiry, scoping and delivering services, contracts and invoicing | Consent when you submit the form; performance of a contract; legitimate interest in responding to business enquiries |
| Contract, project and billing details | You, during an engagement | Delivering services, invoicing, accounting and tax obligations | Contract; legal obligation |
| Technical data: IP address, browser, pages visited, approximate location | Your browser, server logs, analytics (if enabled) | Running and securing the website, understanding what is read | Legitimate interest; consent for non-essential cookies where required |
| Recruitment data: CV, code samples, take-home work | You, when you apply | Assessing your application | Consent; steps before entering a contract |
We do not sell personal data and we do not use it for automated decision-making that produces legal effects.
4. Cookies and analytics
havik.in uses strictly necessary cookies to make the site work. If we enable analytics, we will use a privacy-preserving tool or ask for your consent before setting non-essential cookies, and this section will list them. You can control cookies in your browser settings.
Two Google services load on this site: Google Fonts (typefaces, on every page) and an embedded Google Map (on the contact page). When they load, your browser sends Google your IP address and standard request data. Google's handling of that data is described in its privacy policy.
5. Sharing
We share personal data only with: service providers who host our website, email and business tools under contracts that restrict their use of the data; professional advisers (accountants, lawyers) where necessary; and authorities where the law requires it. Where a client engagement involves processing personal data on the client's behalf, we act as a processor under a written agreement and process only on the client's instructions.
6. International transfers
We are based in India and serve clients worldwide. Where data is transferred from the EU or UK, we rely on standard contractual clauses or another lawful transfer mechanism. Where data is transferred outside India, we do so in accordance with the DPDP Act and any restrictions notified under it.
7. Retention
Enquiry data: up to 24 months after our last contact, unless it becomes part of a contract. Contract and billing data: as long as required by Indian accounting and tax law (currently 8 years). Recruitment data: 12 months after the decision, unless you ask us to keep it longer. Server logs: up to 90 days.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, and logging. Our own encryption protocol, ICEBERG, is used where message content must stay private through servers and storage. No system is perfectly secure; if we become aware of a personal data breach that is likely to affect you, we will notify you and the Data Protection Board of India or the relevant EU authority as required.
9. Your rights
Under the DPDP Act you may: access a summary of the personal data we hold and how it is processed; ask us to correct, complete or update it; ask us to erase it where it is no longer necessary; nominate a person to exercise your rights if you are unable to; and raise a grievance with our Grievance Officer and, if unresolved, with the Data Protection Board of India. Under the GDPR you may also object to processing, request restriction, request portability, withdraw consent at any time, and complain to your supervisory authority. To exercise any right, write to info@havik.in. We may ask you to verify your identity.
10. Children
Our website and services are directed at businesses and adults. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes
We will post changes to this policy on this page with a new "last updated" date. Material changes affecting an existing engagement will be communicated directly.