Building with AI? Ask us about LLM red teaming and ISO 42001.Explore AI security

Legal

Privacy policy.

How Arunima Consulting Pvt. Ltd., operating as Coditing®, collects, uses and protects personal data, and the choices you have.

Effective date: 1 October 2026 · Version: 2.0 · Controller: Arunima Consulting Pvt. Ltd.

We do not sell dataYour personal data is never sold, rented or traded.
No trackingNo analytics, advertising pixels or tracking cookies on this site.
Only what we needWe collect what you send us and the basic logs that keep the site secure.
You stay in controlAccess, correct or delete your data by writing to us.

01Who we are and what this covers

This policy is issued by Arunima Consulting Pvt. Ltd., which operates under the registered trademark Coditing® (“Coditing”, “we”, “us”). We are the data controller (a “data fiduciary” under India’s DPDP Act) for the personal data described here.

It covers www.coditing.com, our contact form, our booking calendar, email correspondence and the consulting engagements we deliver. “Personal data” means any information that identifies you directly, such as your name or email address, or that could identify you when combined with other information.

02What we collect

We keep this website deliberately lean. It has no analytics scripts, advertising pixels or social media trackers. We receive personal data only in these ways:

  • Server logs: standard request data (IP address, browser and device type, page requested, referrer, status code and time) recorded by our hosting provider to deliver and protect the site.
  • Contact form: the details you choose to send, such as your name, work email, company, company stage, the help you need, any deadline and your message.
  • Email: the content and metadata of messages you send to our published addresses.
  • Booking: your name, email and preferred time when you book a call through our scheduling provider.
  • Engagement data: for clients, business contact details, scope documents, technical evidence and confidential artefacts handled under contract and NDA.

We do not embed Google Analytics, Meta Pixel, the LinkedIn Insight Tag or any other third-party tracking script.

03How we use your information

  • To run, maintain and secure the website.
  • To reply to your enquiries and arrange calls.
  • To deliver, support and invoice our services.
  • To meet legal, regulatory, audit and tax obligations.
  • To detect and prevent security incidents, spam and abuse.
  • To send service-related updates. We never send marketing email without your consent.

04Our legal basis

Depending on where you are, laws such as the GDPR, the UK GDPR, India’s Digital Personal Data Protection Act, 2023 and the California Consumer Privacy Act may apply. We rely on:

  • Contract: to perform our service agreements with clients.
  • Consent: when you choose to contact us, submit the form or book a call. You can withdraw consent at any time.
  • Legitimate interests: to operate, secure and improve our website and services, balanced against your rights.
  • Legal obligation: to meet tax, accounting, audit and regulatory requirements.

05Cookies and tracking

The Coditing website does not set first-party cookies and does not use tracking technologies. Your browser may cache files such as images and styles to load pages faster; this is not used to identify you. See our cookie policy for details.

06Third-party services we use

NetlifyHosts the website, encrypts connections and receives contact-form submissions. Processes server logs.
MicrosoftProvides our email and booking calendar.
Google FontsDelivers the website’s typefaces; your browser shares its IP address to download them.
LinkedInOutbound link to our company page only. No LinkedIn tracking is embedded.

A current list of named sub-processors, with their locations, processing scope and safeguards, forms part of our Data Processing Addendum and is available to clients and prospective clients on request.

07When we share data

We do not sell, rent or trade personal data. We share it only:

  • With processors such as hosting, email, accounting and payment providers, under contract.
  • With professional advisers such as auditors, lawyers and insurers, who are bound by confidentiality.
  • When the law requires it, for example in response to a court order or a regulator’s request.
  • With your explicit consent, or with an organisation you direct us to share it with.

08How long we keep it

Server logs7 to 30 days, in line with our hosting provider’s standard.
Contact form and email enquiriesUntil your enquiry is resolved, plus a reasonable follow-up period.
Client engagement recordsFor the engagement and the legally required period afterwards, commonly 7 years in India.
Restricted engagement artefactsAs agreed in the engagement NDA, often 30 to 90 days after delivery.

09International transfers

Coditing is headquartered in India and serves clients worldwide, so your data may be processed outside your country. Where it is, we rely on recognised safeguards such as Standard Contractual Clauses for EU and UK transfers, the EU-US Data Privacy Framework where a provider participates in it, and contractual protections with our sub-processors.

10Your rights

Depending on the law that applies to you, you can:

  • Access the personal data we hold about you.
  • Correct or update inaccurate or incomplete data.
  • Erase data we no longer need, subject to legal retention duties.
  • Restrict or object to certain processing.
  • Withdraw consent at any time, without affecting earlier processing.
  • Port your data to another provider.
  • Nominate another person to exercise your rights, and seek grievance redressal, as provided under India’s DPDP Act.
  • Complain to a supervisory authority, such as the Data Protection Board of India or your local data-protection regulator.

To exercise any of these rights, write to . We respond within the timelines the applicable law sets.

11How we protect your data

As a security firm we apply to ourselves the controls we recommend to clients:

  • TLS 1.2 or higher for data in transit.
  • Encryption at rest in the managed services we use.
  • Role-based, least-privilege access with periodic reviews.
  • Multi-factor authentication on administrative accounts.
  • An incident response process aligned with ISO/IEC 27001 controls.

If a personal data breach affects you, we will notify you and the relevant authorities as the law requires.

12Children’s privacy

Coditing serves organisations, not consumers. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, contact us and we will delete it.

13Changes to this policy

We may update this policy as our services or the law change. When we make a material change, we will update the effective date above and, where appropriate, notify clients and website visitors.

14Contact us

Privacy questions and requests:

Data controller: Arunima Consulting Pvt. Ltd., operating as Coditing®

Registered office: India

Please include “Privacy” in your subject line so your message reaches the right person quickly.